Shibboleth audit logging - Fails to capture client browser IP (x-forwarded-for) in IdP/Tomcat
Cantor, Scott
cantor.2 at osu.edu
Tue Mar 7 12:25:47 EST 2017
On 3/7/17, 12:17 PM, "users on behalf of Jim Fox" <users-bounces at shibboleth.net on behalf of fox at washington.edu> wrote:
> In addition to the other suggestions you really ought to set the
> internalProxies attribute of the RemoteIpValve. That's how you prevent
> just anyone from setting the x-forwarded-for header.
Assuming that whitelists the addresses who can set it, that's a cool feature. Unfortunately the issue I was referring to is that I believe it's possible with some load balancers that support setting it that they don't prevent the client from already setting it and overriding whatever the load balancer might set.
I do not know that F5 does this. I do know that the Citrix NetScaler does. They also refused to fix it.
-- Scott
More information about the users
mailing list