<html><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:10pt"><div>I have a client whose IP address changes between requests. I have been using my test system to let them work out their details. I added <span style="font-size: 13.333333015441895px; color: rgb(34, 34, 34); font-family: Verdana, Geneva, Helvetica, Arial, sans-serif;">consistentAddress="</span><wbr style="font-size: 13.333333015441895px; color: rgb(34, 34, 34); font-family: Verdana, Geneva, Helvetica, Arial, sans-serif;"><span style="font-size: 13.333333015441895px; color: rgb(34, 34, 34); font-family: Verdana, Geneva, Helvetica, Arial, sans-serif;">false" to my session stanza to allow them to test like this. My question is, what is the security risk by allowing this? Does it facilitate man in the middle attacks? I just want to make sure I am not opening a
can of worms here if I migrate that setting to production...</span></div></div></body></html>