PeopleSoft/WebLogic proxy with Shibboleth Native SP and Apache

Cantor, Scott cantor.2 at osu.edu
Wed Jan 23 15:42:38 EST 2013


On 1/23/13 3:31 PM, "Marc Boorshtein" <mboorshtein at gmail.com> wrote:
>
>Isn't this how shib integrates with most apps?  Write an attribute to
>a header and trust the header to identify the user?

When it's necessary, I certainly use server variables when I can.

>> The connector that WebLogic provides for Apache automatically proxies
>>all
>> headers the client sends to WebLogic, so anything spoofed would get
>>there
>> anyway.
>
>Right, but wouldn't the shib proxy over-write whatever inbound headers
>are being spoofed?

It protects the headers it's responsible for. It doesn't touch anything
else.

>RE my last point.  I'd think the shib proxy would have some kind of
>protection against trying to spoof headers, or am I missing something?

My point was what happens if you rely on headers that don't have anything
to do with the SP, which I thought was what was being suggested. Maybe I
was misunderstanding.

-- Scott




More information about the users mailing list