How to support an SP that accepts both http and https on IdP

Nate Klingenstein ndk at internet2.edu
Tue Mar 26 17:13:14 EDT 2013


I should probably strengthen this language.  Specifically, user authentication is often done via password.  In this case, you're not just concerned with an attacker being able to take over a bearer token or a session; it's something more persistent and less tied to an instance, and it can generally be played by the attacker to the IdP at any time.

On Mar 26, 2013, at 21:07 , Nate Klingenstein wrote:

Similarly, I would recommend that the IdP listen only over TLS.  If your metadata reflects this, then users should never be showing up at your IdP on port 80 anyway. Whether or not to redirect users that arrive on port 80 for some reason to 443 is up to your discretion.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130326/6e0f044b/attachment.html 


More information about the users mailing list