Whitelisting relaystate or equivalent

Cantor, Scott cantor.2 at osu.edu
Thu Feb 2 22:49:43 EST 2017


On 2/2/17, 10:37 PM, "users on behalf of Paul Koh" <users-bounces at shibboleth.net on behalf of paul.koh at anacle.com> wrote:

>3.      If the login flow begins from the IdP, the IdP should set the relaystate value

Login flows should not start with the IdP and when they do, coupling that with non-interoperable uses of RelayState is just making matters worse, so no, it's not a good idea to set it.

>  4. The hijacking would have to occur at the point of the user being redirected from the IdP to the SP after authentication
> – there is no way to provide the user with a url which can spoof the initial redirection from the SP for an unauthenticated
> user

Manipulating RelayState is usually trivial at every step of the exchange if that's what the goal is.
 
> I am using the Sibboleth SP v2.6.0.1, with the default ss:mem at the relayState option. The tool’s attach seems to have
> come from a custom cookie with a relaystate value. Is there any way to whitelist the url in such a case?

There are dozens of threads on limiting redirects issued by the SP, just search for redirectLimit.

-- Scott
    
    



More information about the users mailing list