<!DOCTYPE HTML><html>
<head>
<meta name="Generator" content="Amazon WorkMail v3.0-4275">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<title>RE: Issues with Chrome "prefetching" our IdP pages</title>
</head>
<body>
<p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">> - disabling replay attack detection as mentioned by Scott (although he is not recommending it)</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;"> </p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Speaking only for myself, most AuthnRequests are not(and need not be) signed, making the replay check itself generally pointless from a security point of view since anyone can change the value arbitrarily, so I wouldn't speak of it in terms of "attack" detection unless you are signing AuthnRequests in the first place.</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;"> </p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">It's not a general solution to the problem, but for people who are not using signed AuthnRequests, turning off the replay check is an expedient option that is IMHO reasonable.  The header inspection approach you're pursuing would be preferable in the longer term for environments with the expertise and control over the infrastructure to do so.</p><blockquote style="border-left:2px solid #b0b0b7; margin-left:5px; margin-right:0px; padding-left:5px"><!-- end sanitized html --></blockquote>
</body>
</html>