Our Info Security folks want a new IDP URL
Losen, Stephen C (scl)
scl at virginia.edu
Fri Oct 26 09:15:14 EDT 2018
Hi folks,
Our current IDP uses a legacy pubcookie SSO system for authentication via authn/RemoteUser. The pubcookie login server displays the login form and the browser address bar indicates this URL: https://netbadge.virginia.edu/ (NetBadge is our SSO brand name).
Since pubcookie is no longer supported, I will soon deploy IDP 3.4.0 configured to authenticate directly via authn/MFA, authn/Password, and authn/Duo.
Our security folks have an anti-phish education campaign where they instruct folks to beware of counterfeit NetBadge login pages, and to check the URL in the browser address bar.
They were understandably not pleased when I informed them that when the new IDP displays the login page, the browser address bar will say https://shibidp.its.virginia.edu/idp/profile/... They want me to somehow jigger things (perhaps with redirects) so that the browser address bar shows something more "trustworthy".
We have been running a Shibboleth IDP for almost ten years with the above URL (which has been essentially invisible to users so far). Many dozens of SPs have local copies of our IDP metadata that redirect to this hostname. Many of these SPs are hosted by vendors and are out of my control. Plus our IDP metadata is published by InCommon. So I can't see any easy, non-disruptive way to magically reconfigure all the SPs out in the wild to use a different hostname.
That leaves redirect trickery, possibly via F5 iRules. But I think this is very risky and would be a nightmare to maintain and troubleshoot. I would love to point out at least one technical showstopper to end this debate.
Stephen C. Losen
ITS - Systems and Storage
University of Virginia
scl at virginia.edu 434-924-0640
More information about the users
mailing list