PeopleSoft/WebLogic proxy with Shibboleth Native SP and Apache
Cantor, Scott
cantor.2 at osu.edu
Wed Jan 23 15:42:38 EST 2013
On 1/23/13 3:31 PM, "Marc Boorshtein" <mboorshtein at gmail.com> wrote:
>
>Isn't this how shib integrates with most apps? Write an attribute to
>a header and trust the header to identify the user?
When it's necessary, I certainly use server variables when I can.
>> The connector that WebLogic provides for Apache automatically proxies
>>all
>> headers the client sends to WebLogic, so anything spoofed would get
>>there
>> anyway.
>
>Right, but wouldn't the shib proxy over-write whatever inbound headers
>are being spoofed?
It protects the headers it's responsible for. It doesn't touch anything
else.
>RE my last point. I'd think the shib proxy would have some kind of
>protection against trying to spoof headers, or am I missing something?
My point was what happens if you rely on headers that don't have anything
to do with the SP, which I thought was what was being suggested. Maybe I
was misunderstanding.
-- Scott
More information about the users
mailing list