Hacking SHIB_USERID
Murthy Nunna
mnunna at fnal.gov
Fri Sep 11 13:13:56 EDT 2015
Good Afternoon,
We are thinking of implementing Shibboleth in our web server... We are successful in obtaining SHIB_USERID and basing our access on this.
How safe is SHIB_USERID (that is passed from idp to SP) from getting hacked? Can user1 get authenticated by Shibboleth and then present as user2 and proceed with access.
Our environment is : browser<->WebServer with Sibboleth used for authentication.
Browser is typically user pcs windows/mac and Web Server is on Linux
Thanks,
Murthy
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150911/a054ef1c/attachment.html>
More information about the users
mailing list