<div dir="ltr"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Please use OASIS' saml-dev list if you want to carry on general SAML discussion.</blockquote><div>That is very true. This is not related to shiboleth but SAML in general so I will ask my question there.</div><div><br></div><div>Out of curiosity Scott, you mentioned response correlation and the ability to block unsolicited responses as mitigations for man in the middle for SP initiated SSO. How do these stop that problem?</div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div><br></div><div>--</div>Stefan</div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Jun 3, 2021 at 2:22 PM Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">* Stefan Rasmusson <<a href="mailto:rasmusson.stefan@gmail.com" target="_blank">rasmusson.stefan@gmail.com</a>> [2021-06-03 12:23]:<br>
> If the attacker can be between the browser and SP and the IdP and<br>
> browser. It can intercept the response from the IdP and present it<br>
> to SP. The response will correspond to the authnrequest send for the<br>
> original user.<br>
<br>
Well, but the Response (or Assertion) will likely be encrypted to the<br>
SP (providing no information to the "person in the middle") and should<br>
always be signed by the IDP (providing no opportunity to the "person<br>
in the middle" to modify or replace the content of the Response).<br>
If the attacker can only play netcat (intercepting messages and<br>
passing them back and forth) but C.I.A. is all still intact, is that<br>
something to be concerned about?<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>