IdP Initiated SAML and Man in the middle
Cantor, Scott
cantor.2 at osu.edu
Mon Jun 7 12:26:34 UTC 2021
On 6/4/21, 3:06 PM, "users on behalf of Stefan Rasmusson" <users-bounces at shibboleth.net on behalf of rasmusson.stefan at gmail.com> wrote:
> Out of curiosity Scott, you mentioned response correlation and the ability to block unsolicited responses as
> mitigations for man in the middle for SP initiated SSO. How do these stop that problem?
It doesn't, I'm wrong. If you're in between the SP and the client for all activity, then there is no SSO protocol that relies on bearer tokens or cookies that will ever prevent it. The fix for that was token binding, which Google proposed and then killed.
If you can't intercept the IdP traffic, then the fact that Shibboleth, unlike ever other SP, supports address checking against the original assertion is also a mitigation. That's the thing everybody turns off and assures me isn't important.
-- Scott
More information about the users
mailing list