Hacking SHIB_USERID

Murthy Nunna mnunna at fnal.gov
Fri Sep 11 13:13:56 EDT 2015


Good Afternoon,

We are thinking of implementing Shibboleth in our web server... We are successful in obtaining SHIB_USERID and basing our access on this.

How safe is SHIB_USERID (that is passed from idp to SP) from getting hacked? Can user1 get authenticated by Shibboleth and then present as user2 and proceed with access.

Our environment is :   browser<->WebServer with Sibboleth used for authentication.

Browser is typically user pcs windows/mac and Web Server is on Linux

Thanks,
Murthy
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150911/a054ef1c/attachment.html>


More information about the users mailing list