Shibboleth audit logging - Fails to capture client browser IP (x-forwarded-for) in IdP/Tomcat

Cantor, Scott cantor.2 at osu.edu
Tue Mar 7 12:25:47 EST 2017


On 3/7/17, 12:17 PM, "users on behalf of Jim Fox" <users-bounces at shibboleth.net on behalf of fox at washington.edu> wrote:

> In addition to the other suggestions you really ought to set the
>  internalProxies attribute of the RemoteIpValve.  That's how you prevent
>  just anyone from setting the x-forwarded-for header.

Assuming that whitelists the addresses who can set it, that's a cool feature. Unfortunately the issue I was referring to is that I believe it's possible with some load balancers that support setting it that they don't prevent the client from already setting it and overriding whatever the load balancer might set.

I do not know that F5 does this. I do know that the Citrix NetScaler does. They also refused to fix it.

-- Scott




More information about the users mailing list