<div dir="ltr"><div dir="ltr">Thanks for the information, Scott, and apologies for my delayed response.<div><br></div><div>I wonder, with `Idp.session.consistentAddress = false` will Shibboleth log when it sees a user change IP? Our test system does not seem to but I may not have the right logging enabled.</div><div><br></div><div>If the code does not do this, would implementing an idp.session.consistentAddressCondition that logs and always returns true be a reasonable way to achieve this?</div><div><br></div><div>Thanks,</div><div><br></div><div>Max Spicer</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, 22 Mar 2022 at 12:35, Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 3/22/22, 7:35 AM, "users on behalf of Max Spicer via users" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> wrote:<br>
<br>
> I wondered what others have done to mitigate such situations and also if anyone could expand further on the<br>
> risks of disabling consistent address checking entirely if cookies are only ever transmitted over SSL.<br>
<br>
Aside from the risks of XSS attacks, the docs reflect my views on the relevance of TLS in the face of how CAs operate, but also (in the case of the IdP moreso), the fact that people run IdPs with a lot of load balancer proxying that undermines the trust it's possible to have in that layer. It is largely a reference to the insider attack threat. SAML's deployability is balanced by the fact that it makes impersonation of users a lot easier than it ought to be, and session affinity confines that risk to the IdP operator and not half the networking team.<br>
<br>
-- Scott<br>
<br>
<br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div style="font-size:small">Max Spicer - Identity Systems Developer</div><div style="font-size:small">IT Services, University of York<br></div></div></div></div></div></div></div>