"Replay detected of message" causes

Nate Klingenstein ndk at sudonym.me
Wed Apr 19 18:34:54 EDT 2017


> They won't, though, they'll be sent back where they started and can't just back up.

There is no obvious pattern to when or how we're seeing these get
replayed or played outside the initial expiration, but it has been
generally observed with devices that are on constrained networks, and
generally using applications with embedded web browsers.  These
AuthnRequests are not signed nor trusted in any way, so I would like
to error out less frequently if possible.  I'm hearing, that's
impossible.

The alternative is protocols that don't have those bits in the first
place.  Unsolicited responses are the immediate fallback and I would
like more reasons to not do that.

> And all your statistics will become meaningless.

I'm not sure how squelching log warnings is more statistically
meaningful than avoiding the check in the first place, though we don't
collect that auditing data from the IdP anyway.

> When I said you could do it, I meant "under no circumstances should you do it".

You'll forgive the misinterpretation, I hope.


More information about the users mailing list