Shib SP ECP - a few woes
Cantor, Scott
cantor.2 at osu.edu
Tue Oct 15 22:14:03 EDT 2013
On 10/15/13 9:54 PM, "Giovanni Bajo" <rasky at develer.com> wrote:
>>>I've patched out this check. Is this a security issue? Isn't the
>>> signature enough to validate the IdP response, without having to
>>> double-check the consistency of the ACS URL?
>>
>> No.
>
>OK, I'll look for the bug on the other side then.
If you need a justification, the reason is that without the check, a MITM
between the client and SP can unilaterally get the client to return an
assertion to it even if the IdP does a check against what's in the
AuthnRequest. Even signing the request doesn't fix it. With the check, the
attacker has to get between the client and both the SP and IdP.
-- Scott
More information about the users
mailing list