<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
Murthy,
<div class=""><br class="">
</div>
<div class="">SHIB_USERID is not passed from the IdP to the SP. The IdP issues a SAML assertion, which in most cases is a bearer token, which is used and processed by the SP. It’s kinda analogous to the IdP making a session cookie on the SP’s behalf and giving
it to the user, except with security parameters built in. Once the SP receives the assertion, it will map some field in there to SHIB_USERID based on your configuration, particularly attribute-map.xml.</div>
<div class=""><br class="">
</div>
<div class="">Whether the security parameters built into the assertion satisfy your needs depends on your needs, of course. In general, if the session is going to be persisted using a cookie, that’s the weakest link in the system. If not, there are ways you
can use SAML in a more secure way, generally by binding the SAML token to the user agent somehow.</div>
<div class=""><br class="">
</div>
<div class="">SHIB_USERID is a header variable and inherent to the same vulnerabilities as all header variables, much of which will depend on the web environment in which you’re operating. Environment variables are preferred to rule out all doubt, but headers
are not the lowest lying fruit in most instances either.</div>
<div class=""><br class="">
</div>
<div class="">This document should still be pretty useful, though there’s almost certainly errata and it doesn’t cover everything.</div>
<div class=""><br class="">
</div>
<div class=""><a href="http://docs.oasis-open.org/security/saml/v2.0/saml-sec-consider-2.0-os.pdf" class="">http://docs.oasis-open.org/security/saml/v2.0/saml-sec-consider-2.0-os.pdf</a></div>
<div class=""><br class="">
</div>
<div class="">Take care,</div>
<div class="">Nate.</div>
<div class=""><br class="">
<div>
<blockquote type="cite" class="">
<div class="">On Sep 11, 2015, at 11:13 AM, Murthy Nunna <<a href="mailto:mnunna@fnal.gov" class="">mnunna@fnal.gov</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div class="WordSection1" style="page: WordSection1; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;">
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
Good Afternoon,<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<o:p class=""> </o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
We are thinking of implementing Shibboleth in our web server… We are successful in obtaining SHIB_USERID and basing our access on this.<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<o:p class=""> </o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
How safe is SHIB_USERID (that is passed from idp to SP) from getting hacked? Can user1 get authenticated by Shibboleth and then present as user2 and proceed with access.<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<o:p class=""> </o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
Our environment is : browser<->WebServer with Sibboleth used for authentication.<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<o:p class=""> </o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
Browser is typically user pcs windows/mac and Web Server is on Linux<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<o:p class=""> </o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
Thanks,<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
Murthy<o:p class=""></o:p></div>
</div>
<span style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;" class="">--<span class="Apple-converted-space"> </span></span><br style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class="">
<span style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;" class="">To
unsubscribe from this list send an email to<span class="Apple-converted-space"> </span></span><a href="mailto:users-unsubscribe@shibboleth.net" style="color: rgb(149, 79, 114); text-decoration: underline; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class="">users-unsubscribe@shibboleth.net</a></div>
</blockquote>
</div>
<br class="">
</div>
</body>
</html>