Suggestions to handle IP Mismatch Issues
Cantor, Scott
cantor.2 at osu.edu
Wed Dec 11 11:43:28 EST 2013
On 12/11/13, 11:37 AM, "ragadeep" <ragadeep99 at hotmail.com> wrote:
>
>I meant if there was a way for SP to handle this without trying to
>re-initiate the session given certain network parameters like sessions
>expected from know network gateways.
Short of whitelisting address ranges to bypass address checks, I don't
know what you think is possible.
Either it checks the address or it doesn't, so all you're doing is turning
that into "check under conditions X, Y, Z, don't check under conditions A,
B, C".
If you want to file a RFE, feel free. The SP is feature frozen for the
time being.
>>.... or you would need to stop using the SP session as the primary
>>mechanism.
>
>Could you please elaborate on this or point me in the right direction?
I did, I mean lazy sessions.
>I'll look into using Passive/Lazy sessions and it might an approach we
>can try. We have an IdP initiated SSO setup and if the SP tries to
>initiate the session when address changes it won't work as the IdP will
>reject the request.
Then you really cannot use active protection rules. The session would
eventually timeout and you'd be in the same situation.
-- Scott
More information about the users
mailing list