Q in SP config and DS URL
Nate Klingenstein
nate.klingenstein at utah.edu
Thu Feb 25 14:28:24 EST 2016
any website can redirect any user agent to any other site, of course,
including a fake DS that would redirect you to a fake IDP that looked
like your own SAML IDP.
This is the crux of the issue. It’s also a consideration for IdP-initiated
SSO, which usually can’t validate the target URL to which a user is being
sent. You’re “kinda” part of the attack vector, but if the ultimate bug is
users not paying attention, that will be hard to fix.
https://issues.oasis-open.org/browse/SECURITY-12
EV certificates will save us. Probably.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160225/c9b9d1e3/attachment-0001.html>
More information about the users
mailing list