IdP Initiated SAML and Man in the middle

Cantor, Scott cantor.2 at osu.edu
Mon Jun 7 12:26:34 UTC 2021


On 6/4/21, 3:06 PM, "users on behalf of Stefan Rasmusson" <users-bounces at shibboleth.net on behalf of rasmusson.stefan at gmail.com> wrote:

>  Out of curiosity Scott, you mentioned response correlation and the ability to block unsolicited responses as
> mitigations for man in the middle for SP initiated SSO. How do these stop that problem?

It doesn't, I'm wrong. If you're in between the SP and the client for all activity, then there is no SSO protocol that relies on bearer tokens or cookies that will ever prevent it. The fix for that was token binding, which Google proposed and then killed.

If you can't intercept the IdP traffic, then the fact that Shibboleth, unlike ever other SP, supports address checking against the original assertion is also a mitigation. That's the thing everybody turns off and assures me isn't important.

-- Scott




More information about the users mailing list