IdP session for client with private IP
David Bantz
dabantz at alaska.edu
Wed May 22 18:40:42 EDT 2013
Our institution is looking to expand use of private address space. The proposed change would have local clients get an IdP session with a private IP address. Of course in going to external (cloud) SPs, the client will present a different public IP address. [We currently have lots of clients using private IP addresses, but when getting to the IdP they have a translated public IP address so currently clients use (the same) public IP address in communications with both the IdP and SPs.]
I'm trying to guess what effect that change (clients using a different IP address to IdP and SP) will have. The following suggests that at least some SPs will be using the default setting to check and refuse to create an SP session.
> checkAddress(boolean) (default is true)
> The IdP will place the IP address of the user agent it authenticated into the assertions it issues. When true, the SP will check this address against the address of the client presenting an assertion before creating a session. While useful for security, NAT and proxy usage (as well as IPv6 support on only either the webserver hosting the IdP or the SP) often make this setting a source of errors.
<https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessions>
David Bantz
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130522/33c92c9b/attachment.html
More information about the users
mailing list