Issues with Chrome "prefetching" our IdP pages
Nate Klingenstein
ndk at signet.id
Mon Oct 15 18:38:35 EDT 2018
> - disabling replay attack detection as mentioned by Scott (although he is not recommending it)
Speaking only for myself, most AuthnRequests are not(and need not be) signed, making the replay check itself generally pointless from a security point of view since anyone can change the value arbitrarily, so I wouldn't speak of it in terms of "attack" detection unless you are signing AuthnRequests in the first place.
It's not a general solution to the problem, but for people who are not using signed AuthnRequests, turning off the replay check is an expedient option that is IMHO reasonable. The header inspection approach you're pursuing would be preferable in the longer term for environments with the expertise and control over the infrastructure to do so.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181015/64b036fe/attachment.html>
More information about the users
mailing list