PeopleSoft/WebLogic proxy with Shibboleth Native SP and Apache

Marc Boorshtein mboorshtein at gmail.com
Wed Jan 23 15:31:33 EST 2013


>
> That won't protect you. If you're talking about the headers the SP is
> handling, then sure, but by definition you aren't, since you're assuming
> that one could omit the application from it. So assuming you mean a custom
> header the application is relying on, that would be a bug in the
> application to assume such a header were meaningful.
>

Isn't this how shib integrates with most apps?  Write an attribute to
a header and trust the header to identify the user?

> The connector that WebLogic provides for Apache automatically proxies all
> headers the client sends to WebLogic, so anything spoofed would get there
> anyway.

Right, but wouldn't the shib proxy over-write whatever inbound headers
are being spoofed?

>
> Note that you have a general point, which is that it's asking for security
> issues to selectively do this anyway, for other reasons. But this would be
> a more specific flaw that would bite you regardless.
>

RE my last point.  I'd think the shib proxy would have some kind of
protection against trying to spoof headers, or am I missing something?

> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list