PeopleSoft/WebLogic proxy with Shibboleth Native SP and Apache

Marc Boorshtein mboorshtein at gmail.com
Wed Jan 23 15:44:24 EST 2013


On Wed, Jan 23, 2013 at 3:42 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 1/23/13 3:31 PM, "Marc Boorshtein" <mboorshtein at gmail.com> wrote:
>>
>>Isn't this how shib integrates with most apps?  Write an attribute to
>>a header and trust the header to identify the user?
>
> When it's necessary, I certainly use server variables when I can.
>

Sure


>>> The connector that WebLogic provides for Apache automatically proxies
>>>all
>>> headers the client sends to WebLogic, so anything spoofed would get
>>>there
>>> anyway.
>>
>>Right, but wouldn't the shib proxy over-write whatever inbound headers
>>are being spoofed?
>
> It protects the headers it's responsible for. It doesn't touch anything
> else.
>

Perfect

>>RE my last point.  I'd think the shib proxy would have some kind of
>>protection against trying to spoof headers, or am I missing something?
>
> My point was what happens if you rely on headers that don't have anything
> to do with the SP, which I thought was what was being suggested. Maybe I
> was misunderstanding.
>

Yes, I'm pretty sure we're talking aobut the same thing.  Just checking.

Thanks


More information about the users mailing list