AJP proxy of request environment

Cantor, Scott cantor.2 at osu.edu
Fri Jul 20 17:15:21 EDT 2012


On 7/20/12 5:09 PM, "Chad La Joie" <lajoie at itumi.biz> wrote:
>
>Well, the HTTP proxy method isn't any more or less secure than the AJP
>protocol.  In both cases you have to trust that there is no MITM.

He's not talking about the security of the proxying, just the requirement
to use headers in the SP, which have to be hardened by the SP against the
client (no MITM).

-- Scott



More information about the users mailing list