Shibboleth audit logging - Fails to capture client browser IP (x-forwarded-for) in IdP/Tomcat

Jim Fox fox at washington.edu
Tue Mar 7 12:31:37 EST 2017


>
>> In addition to the other suggestions you really ought to set the
>>  internalProxies attribute of the RemoteIpValve.  That's how you prevent
>>  just anyone from setting the x-forwarded-for header.
>
> Assuming that whitelists the addresses who can set it, that's a cool feature. Unfortunately the issue I was referring to is that I believe it's possible with some load balancers that support setting it that they don't prevent the client from already setting it and overriding whatever the load balancer might set.
>
> I do not know that F5 does this. I do know that the Citrix NetScaler does. They also refused to fix it.
>

Yes, it whitelists addresses.  I set the header with an F5 iRule, so I 
know it always gets set correctly.

Jim


More information about the users mailing list