SP 2.x doesn't respect consistentAddress="false" setting
Cantor, Scott
cantor.2 at osu.edu
Wed Sep 20 10:41:02 EDT 2017
On 9/20/17, 10:24 AM, "users on behalf of Mark Vinkx" <users-bounces at shibboleth.net on behalf of mark.vinkx at uzleuven.be> wrote:
> Setting consistentAddress="false" checkAddress="false" does not disable the checking of the client IP address and a the existing
> session is not accepted
Then I guess somebody should file a bug, but if nobody does I can promise you I won't ever remember to look at it. But as a "feature" this is not one that anybody should ever use. I'm happy to fix it but I would never consider using it, it's just not sound security to use bearer cookies with no other constraint.
> I tried using the REMOTE_ADDR setting but then I get in a loop between SP and our adfs IDP.
Well, that's something else, but I can't debug a loop for somebody else's system. Other than this specific check causing the session to invalidate there's nothing else I can think of that would cause a loop.
-- Scott
More information about the users
mailing list