Protecting the root context/path
James W. Anderson
jamesanderson at coca-cola.com
Wed Oct 15 13:48:39 EDT 2014
Can Shibboleth SP secure the root folder of a website? I seem to recall reading that this wasn't supported, and vaguely remember that IIS service provider would not work when I specified "/" as the secure location; seems like it just ignored the setting altogether and the site had no security.
Someone at my company implemented the Confluence Wiki product and secured with Shibboleth SP, they set it up to run in the path /confluence to work with Shibboleth, and twice now the site has been brought down by SQL injection attacks. They'd like to secure the whole site, including the root, to try to prevent further attacks, and I want to verify that this configuration is supported.
Thanks,
James Anderson
Alpharetta, Georgia USA
________________________________
CONFIDENTIALITY NOTICE
NOTICE: This message is intended for the use of the individual or entity to which it is addressed and may contain information that is confidential, privileged and exempt from disclosure under applicable law. If the reader of this message is not the intended recipient, you are hereby notified that any printing, copying, dissemination, distribution, disclosure or forwarding of this communication is strictly prohibited. If you have received this communication in error, please contact the sender immediately and delete it from your system. Thank You.
________________________________
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141015/5e9018f4/attachment.html
More information about the users
mailing list