Shibboleth audit logging - Fails to capture client browser IP (x-forwarded-for) in IdP/Tomcat

Jim Fox fox at washington.edu
Tue Mar 7 12:17:36 EST 2017


In addition to the other suggestions you really ought to set the 
internalProxies attribute of the RemoteIpValve.  That's how you prevent 
just anyone from setting the x-forwarded-for header.

Jim


On Tue, 7 Mar 2017, Kevin Foote wrote:

> Date: Tue, 7 Mar 2017 08:54:33
> From: Kevin Foote <kevin.foote at colorado.edu>
> To: Shib Users <users at shibboleth.net>
> Reply-To: Shib Users <users at shibboleth.net>
> Subject: Re: Shibboleth audit logging - Fails to capture client browser IP
>     (x-forwarded-for) in IdP/Tomcat
> 
>
>> On Mar 7, 2017, at 09:50, Petursson, Sigurdur <spetursson at miami.edu> wrote:
>>
>> Thanks Kevin. We are still running IdP version 2.38. Your documentation only applies to version 3 correct?
>
> That version is very unsupported, YMMV. You need to update to the latest software.
>
> The same documentation is available for IdPv2.
>
> https://wiki.shibboleth.net/confluence/display/SHIB2/IdPLogging
>
>
> --------
> thanks
> kevin.foote
> -- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>


More information about the users mailing list