security of "shibuseheaders"

Cantor, Scott cantor.2 at osu.edu
Wed Nov 23 14:26:49 EST 2016


On 11/23/16, 9:41 AM, "users on behalf of Liam Hoekenga" <users-bounces at shibboleth.net on behalf of liamr at umich.edu> wrote:

> If headers + spoof checking is as insecure as the spoof checking article suggests, should we not use the IIS
> module for sensitive applications?

I can't tell you what to do. There is no choice, you can use headers or not use IIS. If you don't need to use headers, there's just no rational reason to use them. That's the point of the warnings.

In the almost ten or so years since the spoofing issues were identified and mitigated, I'm not aware of any successful attacks against it.

-- Scott




More information about the users mailing list