timeout settings
Cantor, Scott
cantor.2 at osu.edu
Thu Jun 20 12:40:41 EDT 2019
On 6/20/19, 12:34 PM, "users on behalf of Lohr, Donald" <users-bounces at shibboleth.net on behalf of lohrda at jmu.edu> wrote:
> Are local browser cookies for SSO, IdP and SP login created and used
> that contain active session/timeout values that could be misused?
Shibboleth software applies timeouts based on data either on the server or managed using its own security components to prevent tampering.
> Unfortunately, shared machines are a reality in our world with labs,
> kiosks, teaching computers in classrooms and at student staffed
> reception areas (to name the big ones).
And what I'm saying is that's game over, with no practical mitigations, so at that point you should disable SSO for those address ranges when they can be known. When they can't, you're vulnerable no matter what you do. No reasonable timeout works without making SSO as a whole useless for everybody else.
-- Scott
More information about the users
mailing list