Shibboleth IdP in a WAF

Cantor, Scott cantor.2 at osu.edu
Mon Apr 15 12:34:00 UTC 2024


> Can anyone else share how they are accomplishing this?

The lockout feature inside the IdP, but that's not about DOS protection, which is a network consideration. You can't do anything about that at the app layer without spending far more time than makes sense, and there would be other attacks possible below layer 7 anyway.

> Is there a  way to add a response header to indicate when a failure
> occurs?

No, but it's a reasonable request. There probably is a way to hack somethiing in there based on a custom audit extractor function running for the password flow audit log.

-- Scott




More information about the users mailing list