Shibboleth IdP in a WAF
Cantor, Scott
cantor.2 at osu.edu
Mon Apr 15 12:34:00 UTC 2024
> Can anyone else share how they are accomplishing this?
The lockout feature inside the IdP, but that's not about DOS protection, which is a network consideration. You can't do anything about that at the app layer without spending far more time than makes sense, and there would be other attacks possible below layer 7 anyway.
> Is there a way to add a response header to indicate when a failure
> occurs?
No, but it's a reasonable request. There probably is a way to hack somethiing in there based on a custom audit extractor function running for the password flow audit log.
-- Scott
More information about the users
mailing list