<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">Our institution is looking to expand use of private address space. &nbsp;The proposed change would have local clients get an IdP session with a private IP address. &nbsp; Of course in going to external (cloud) SPs, the client will present a different public IP address. &nbsp;[We currently have lots of clients using private IP addresses, but when getting to the IdP they have a translated public IP address so currently clients use (the same) public IP address in communications with both the IdP and SPs.]<div><br></div><div>I'm trying to guess what effect that change (clients using a different IP address to IdP and SP) will have. &nbsp;The following suggests that at least some SPs will be using the default setting to check and refuse to create an SP session. &nbsp;</div><div><div><br></div><div><blockquote type="cite"><code style="margin-top: 0px; color: rgb(51, 51, 51); font-size: 13.63636302947998px; line-height: 17.329545974731445px; text-align: left; background-color: rgb(255, 255, 255); ">checkAddress</code><span style="color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; font-size: 13.63636302947998px; line-height: 17.329545974731445px; text-align: left; background-color: rgb(255, 255, 255); ">(boolean) (default is true)</span><ul style="font-size: 13.63636302947998px; line-height: 17.329545974731445px; margin-bottom: 0px; margin-left: 0px; padding-left: 3em; list-style-position: outside; padding-top: 0px; margin-top: 0px; color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; text-align: left; background-color: rgb(255, 255, 255); "><li style="font-size: 10pt; line-height: 13pt; margin: 0px; padding: 0px;">The IdP will place the IP address of the user agent it authenticated into the assertions it issues. When true, the SP will check this address against the address of the client presenting an assertion before creating a session. While useful for security, NAT and proxy usage (as well as IPv6 support on only either the webserver hosting the IdP or the SP) often make this setting a source of errors.</li></ul></blockquote><div>&lt;<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessions">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessions</a>&gt;</div></div></div><div><br></div><div>David Bantz</div></body></html>