Q in SP config and DS URL

Nate Klingenstein nate.klingenstein at utah.edu
Thu Feb 25 14:28:24 EST 2016


any website can redirect any user agent to any other site, of course,
including a fake DS that would redirect you to a fake IDP that looked
like your own SAML IDP.

This is the crux of the issue.  It’s also a consideration for IdP-initiated
SSO, which usually can’t validate the target URL to which a user is being
sent.  You’re “kinda” part of the attack vector, but if the ultimate bug is
users not paying attention, that will be hard to fix.

https://issues.oasis-open.org/browse/SECURITY-12

EV certificates will save us.  Probably.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160225/c9b9d1e3/attachment-0001.html>


More information about the users mailing list