Shibboleth audit logging - Fails to capture client browser IP (x-forwarded-for) in IdP/Tomcat
Jim Fox
fox at washington.edu
Tue Mar 7 12:31:37 EST 2017
>
>> In addition to the other suggestions you really ought to set the
>> internalProxies attribute of the RemoteIpValve. That's how you prevent
>> just anyone from setting the x-forwarded-for header.
>
> Assuming that whitelists the addresses who can set it, that's a cool feature. Unfortunately the issue I was referring to is that I believe it's possible with some load balancers that support setting it that they don't prevent the client from already setting it and overriding whatever the load balancer might set.
>
> I do not know that F5 does this. I do know that the Citrix NetScaler does. They also refused to fix it.
>
Yes, it whitelists addresses. I set the header with an F5 iRule, so I
know it always gets set correctly.
Jim
More information about the users
mailing list