Detection of replay attack in clustered environment

KajoKrtko acojakochces at gmail.com
Tue Feb 11 03:59:10 EST 2014


Thanks for reply Scott, 

Anyway I'd like to ask this: Can assertion id be extracted and passed to my
protected application? I'm using this parameters pasing:
<ApplicationDefaults entityID="relyingPartyId-Clone" 
                         REMOTE_USER="eppn persistent-id targeted-id
affiliation"
                         signing="false" 
                         encryption="false"
                         attributePrefix="AJP_">

So I'd be lucky if there is a way how to define and add assertion id to
REMOTE_USER. Maybe it is defined be default and I just don't know how to add
it. Or how to read it. And that "be default" I mean some parameter like
this:

String shibbolethEntityId = (String)
request.getAttribute("Shib-Identity-Provider");
String dateTime = (String)
request.getAttribute("Shib-Authentication-Instant");

Is there and assertion id?

-Kajo



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Detection-of-replay-attack-in-clustered-environment-tp7594992p7595058.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list