Can the _shibboleth_ credentials be transferred?
Peter Schober
peter.schober at univie.ac.at
Wed Oct 17 06:38:35 EDT 2018
* Daniel Södling <daniel.sodling at pdsvision.se> [2018-10-17 08:47]:
> That sounds like it would work
That depends on what the specific error is you've been seeing, which
you still haven't disclosed.
I'd expect the SP to log something about the fact that it recieved the
session cookie from a different IP address. If that's the case,
disabling the binding of sessions to IP addresses would "fix" that
issue, at the cost of weakening security for the whole setup.
You could file a wishlist issue about adding localhost's IPs to the
set of IP addresses from which such cookies are always allowed. While
impersonating the subject's browser is still fundamentally "wrong"
that would at least avoid the need to disable that security feature
wholesale.
-peter
More information about the users
mailing list