security of "shibuseheaders"

Cantor, Scott cantor.2 at osu.edu
Wed Nov 23 15:22:43 EST 2016


On 11/23/16, 3:20 PM, "users on behalf of Eric Goodman" <users-bounces at shibboleth.net on behalf of Eric.Goodman at ucop.edu> wrote:

> Just for clarity, is this properly parsed as the following?:
>    
>    "In the almost ten or so years since the [Shib header] spoofing issues were identified and mitigated, I'm not
> aware of any successful attacks against it [where the Shib SP allowed a spoofed header to be passed to the
> resource it was directly protecting]."

Yes, I'm just talking about the SP.

-- Scott




More information about the users mailing list