"Replay detected of message" causes

Klingenstein, Nate nklingenstein at calstate.edu
Wed Apr 19 17:50:08 EDT 2017


> It's far worse to "trap" people without a way to back up


Known and acknowledged but not a primary concern in this specific deployment because of SPNEGO and users that are quite willing to sit on the back button until they get... somewhere.


> What you want to do is remove the rules, and anybody is free to use any inbound interceptor flow they like or none at all.


Thank you.  This is just the splice point he needed.

________________________________
From: users <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
Sent: Wednesday, April 19, 2017 2:45:05 PM
To: Shib Users
Subject: Re: "Replay detected of message" causes

On 4/19/17, 5:32 PM, "users on behalf of Nate Klingenstein" <users-bounces at shibboleth.net on behalf of ndk at sudonym.me> wrote:

> I know it's forbidden by specification to not check and it will void
> his warranty, but is it intended that the
> OptionalMessageReplaySecurityHandler and
> OptionalMessageLifetimeSecurityHandler beans declared in
> system\flows\saml\security-beans.xml be usable in production?

It's far worse to "trap" people without a way to back up, or artifically inflate login counts and traffic. The main purpose of the check is in fact to make sure the back button causes a defined error since it *can't* do anything useful.

Also, they don't do what you think they do anyway. Optional means "if it's not possible to check, don't fail". It doesn't mean "if it fails, don't care".

What you want to do is remove the rules, and anybody is free to use any inbound interceptor flow they like or none at all.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170419/e13ed39f/attachment.html>


More information about the users mailing list