Supporting change of IP address during Shibboleth sessions

Cantor, Scott cantor.2 at osu.edu
Tue Mar 22 12:34:57 UTC 2022


On 3/22/22, 7:35 AM, "users on behalf of Max Spicer via users" <users-bounces at shibboleth.net on behalf of users at shibboleth.net> wrote:

> I wondered what others have done to mitigate such situations and also if anyone could expand further on the
> risks of disabling consistent address checking entirely if cookies are only ever transmitted over SSL.

Aside from the risks of XSS attacks, the docs reflect my views on the relevance of TLS in the face of how CAs operate, but also (in the case of the IdP moreso), the fact that people run IdPs with a lot of load balancer proxying that undermines the trust it's possible to have in that layer. It is largely a reference to the insider attack threat. SAML's deployability is balanced by the fact that it makes impersonation of users a lot easier than it ought to be, and session affinity confines that risk to the IdP operator and not half the networking team.

-- Scott




More information about the users mailing list