<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
I've seen examples with mod_reqtimeout (ReadRequestTimeout) suggesting it could help mitigate DDoS; mod_security could be configured for something similar, though IMO the former is a bit more straightforward.
<div class="">
<div class="">
<div class="">
<div style="margin: 0px; font-size: 11px; line-height: normal; font-family: Menlo;" class="">
<span style="font-variant-ligatures: no-common-ligatures" class=""><br class="">
</span></div>
<div style="margin: 0px; font-size: 11px; line-height: normal; font-family: Menlo;" class="">
<span style="font-variant-ligatures: no-common-ligatures" class="">Tom.</span></div>
<div style="margin: 0px; font-size: 11px; line-height: normal; font-family: Menlo;" class="">
<span style="font-variant-ligatures: no-common-ligatures" class=""><br class="">
</span></div>
<div>
<blockquote type="cite" class="">
<div class="">On Aug 23, 2017, at 1:55 AM, Glenn Wearen <<a href="mailto:glenn.wearen@heanet.ie" class="">glenn.wearen@heanet.ie</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div text="#000000" bgcolor="#FFFFFF" class="">
<p class=""><tt class="">We put </tt><tt class="">modsecurity on our A</tt><tt class="">pache hosts</tt><tt class=""> (</tt><tt class="">that fro</tt><tt class="">nt the IdP), it will
</tt><tt class="">offer a degree</tt><tt class=""> of DoS protection but not enough</tt><tt class=""> for DDoS</tt><tt class="">.</tt><tt class=""> Modsec has been
</tt><tt class="">particularly</tt><tt class=""> usef</tt><tt class="">ul </tt><tt class="">thr</tt><tt class="">ough</tt><tt class=""> blacklisting any URL other than the IdP's known URL's.  This allows us to use 404's in our failonstatus apache proxy settings,
 which the Tomcat will sometimes return in if the IdP app has crashed (usually triggered by underlying problem with database, ldap, filesysystem etc and not the app).</tt></p>
<p class=""><tt class="">It also helps with zero day vulnerabilities, not that we've ever had to use it :-)</tt></p>
<p class=""><tt class="">Regards</tt></p>
<p class=""><tt class="">Glenn</tt><br class="">
</p>
<div class="moz-cite-prefix">On 22/08/2017 21:23, Joshua Brodie wrote:<br class="">
</div>
<blockquote type="cite" cite="mid:CAO-t1wGgV7Cq=PFVytOvBxXLzhB1KFbe2FJcdScySMb04sv_vw@mail.gmail.com" class="">
<div dir="ltr" class="">
<div class="">
<div class="">
<div class="">Not directly Shibboleth related.....but there is no better audience than this user group, I will live with taking the risk of posting off topic.<br class="">
<br class="">
</div>
Assuming you don't have a big budget -- and no infrastructure defenses -- beyond bare bones firewall -- how would you protect the IdP from a DoS type attack...<br class="">
<br class="">
</div>
We have had brute force attacks -- which become DoS events due to the load....are thinking of implementing Fail2Ban (it won't protect against DoS but at least we will be alerted and can mitigate brute force by shutting down the IP on the server level -- the
 upstream firewall will only kick in after a few hours due to manual update by external vendor).<br class="">
<br class="">
</div>
Any other thoughts?<br class="">
</div>
<br class="">
<fieldset class="mimeAttachmentHeader"></fieldset> <br class="">
</blockquote>
<br class="">
</div>
-- <br class="">
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">
users-unsubscribe@shibboleth.net</a></div>
</blockquote>
</div>
<br class="">
</div>
</div>
</div>
</body>
</html>