Protecting the root context/path

Cantor, Scott cantor.2 at osu.edu
Wed Oct 15 13:56:00 EDT 2014


On 10/15/14, 1:48 PM, "James W. Anderson" <jamesanderson at coca-cola.com>
wrote:

>Can Shibboleth SP secure the root folder of a website?

Yes.

> I seem to recall reading that this wasn¹t supported, and vaguely
>remember that IIS service provider would not work when I specified ³/² as
>the secure location; seems like it just ignored
> the setting altogether and the site had no security.

I can't speak to what anybody's system does, but the SP knows how to
exempt its own handlers from rules and there's nothing else that makes the
root special apart from self-inflicted problems like having error template
content that can't be served up.

Is it a good idea to do? Not in most cases, it's too easy to screw up, but
the SP doesn't care.

-- Scott



More information about the users mailing list