Reducing the number of re-authentications

Cantor, Scott cantor.2 at osu.edu
Thu Mar 7 21:12:43 EST 2019


> Does the Shibboleth IdP support some kind of filter or predicate for that check?

For the whole session it's a property, on/off. Every login flow has a more fine grained condition property for controlling reuse at a programmable level.

Either address controls are effective and hard to circumvent or they aren't. I have heard both sides. If they're so weak that they don't matter then we have all sorts of server-side controls and policies that amount to nothing and have a lot of problems. I suspect they're more effective than that, in which case it's a real reduction in security to do this given the weak security of browsers.

Token binding was supposed to fix this and then Google all but killed it.

-- Scott




More information about the users mailing list