PeopleSoft/WebLogic proxy with Shibboleth Native SP and Apache
Marc Boorshtein
mboorshtein at gmail.com
Wed Jan 23 15:31:33 EST 2013
>
> That won't protect you. If you're talking about the headers the SP is
> handling, then sure, but by definition you aren't, since you're assuming
> that one could omit the application from it. So assuming you mean a custom
> header the application is relying on, that would be a bug in the
> application to assume such a header were meaningful.
>
Isn't this how shib integrates with most apps? Write an attribute to
a header and trust the header to identify the user?
> The connector that WebLogic provides for Apache automatically proxies all
> headers the client sends to WebLogic, so anything spoofed would get there
> anyway.
Right, but wouldn't the shib proxy over-write whatever inbound headers
are being spoofed?
>
> Note that you have a general point, which is that it's asking for security
> issues to selectively do this anyway, for other reasons. But this would be
> a more specific flaw that would bite you regardless.
>
RE my last point. I'd think the shib proxy would have some kind of
protection against trying to spoof headers, or am I missing something?
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list