Impersonate and RemoteAccess

Marco Naimoli marco.naimoli at unipd.it
Thu May 20 15:37:52 UTC 2021


Hello, thank you for the warning: I don't believe to reuse cached results
but I completely agree with you,
it's better to do a deeper analysis to avoid security problems
Thank you very much
Marco

Il giorno gio 20 mag 2021 alle ore 15:46 Cantor, Scott <cantor.2 at osu.edu>
ha scritto:

> On 5/20/21, 9:22 AM, "users on behalf of Marco Naimoli" <
> users-bounces at shibboleth.net on behalf of marco.naimoli at unipd.it> wrote:
>
> >    itself. I'm sure it's not the only way to do this, and it's not the
> best way, but it's an easy way
>
> If you're a member and you want to dive into the details in a support case
> so I can help analyze the risks, feel free, but I can't do that on list
> obviously, I'm just leaving it as a friendly warning that I really can't
> say what you're doing is clearly "safe" without more analysis.
>
> I suspect one way to keep it "safer", and maybe this is what you did, is
> to prevent it from caching the RemoteUser result and make sure it re-runs
> each time so that a previous decision doesn't contaminate a later one. You
> don't do that with timeouts, though, that's done with a condition attached
> to the RemoteUser flow setting the caching of results to false, specifics
> vary by version. Pre 4.1 it's a field on the bean in general-authn.xml
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210520/10244ea7/attachment.htm>


More information about the users mailing list