Shibboleth Service Provider Security Advisory [17 March 2021]

Wessel, Keith kwessel at illinois.edu
Wed Mar 17 17:35:23 UTC 2021


https://marc.info/?l=shibboleth-announce&m=161598315618467&w=2

It went to the announce list, not the users list. If you're not on the announce list, you probably should be.

To subscribe, send mail to announce-subscribe at shibboleth.net<mailto:announce-subscribe at shibboleth.net>

Keith


From: users <users-bounces at shibboleth.net> On Behalf Of Ullfig, Roberto Alfredo
Sent: Wednesday, March 17, 2021 12:06 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: Shibboleth Service Provider Security Advisory [17 March 2021]

Where can I find the original post this thread?

---
Roberto Ullfig - rullfig at uic.edu
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
Sent: Wednesday, March 17, 2021 8:07 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: Shibboleth Service Provider Security Advisory [17 March 2021]

On 3/17/21, 8:51 AM, "users on behalf of Ondrej Kosarko" <users-bounces at shibboleth.net on behalf of kosarko at ufal.mff.cuni.cz> wrote:

>    I fail to understand if the change in sp v3.2.1 changes the behavior when using redirectErrors in the Errors
> element.

Has nothing to do with that feature except insofar as the exploit effectively could alter what's in the redirect.

However, it stands to reason that anybody relying on error redirection is hard pressed to prevent the same bug in their own code.

Error handling is hard and it is the achilles heel of my "never put identity code inside applications" approach, probably a fatal one. Unfortunately the inverse is unworkable because it means applications are effectively incapable of evolving their identity support (*), and that's not viable either. Don't really have an answer.

-- Scott

(*) Yes, you can change applications. Doesn't happen, not on a campus, at scale.

--
For Consortium Member technical support, see https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=04%7C01%7Crullfig%40uic.edu%7Cfb2c2de89d434230171c08d8e94c9a8c%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637515862517797989%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=Q7dgC%2B603e3gnV12OJ1oyWnRm1weY9uif862q6BT96c%3D&reserved=0<https://urldefense.com/v3/__https:/nam04.safelinks.protection.outlook.com/?url=https*3A*2F*2Fwiki.shibboleth.net*2Fconfluence*2Fx*2FcoFAAg&data=04*7C01*7Crullfig*40uic.edu*7Cfb2c2de89d434230171c08d8e94c9a8c*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C637515862517797989*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C1000&sdata=Q7dgC*2B603e3gnV12OJ1oyWnRm1weY9uif862q6BT96c*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSU!!DZ3fjg!pv6Z-kXTsYu4uZEfEokksnBMoFBTlma_xC3l_vdHkEXmS_sRDYOWfK6jW4OQL0vvQQ$>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210317/11621f8a/attachment.htm>


More information about the users mailing list