AJP proxy of request environment
Cantor, Scott
cantor.2 at osu.edu
Fri Jul 20 17:15:21 EDT 2012
On 7/20/12 5:09 PM, "Chad La Joie" <lajoie at itumi.biz> wrote:
>
>Well, the HTTP proxy method isn't any more or less secure than the AJP
>protocol. In both cases you have to trust that there is no MITM.
He's not talking about the security of the proxying, just the requirement
to use headers in the SP, which have to be hardened by the SP against the
client (no MITM).
-- Scott
More information about the users
mailing list