Skip to Content.
Sympa Menu

shibboleth-dev - RE: Multiple targets in a single domain?

Subject: Shibboleth Developers

List archive

RE: Multiple targets in a single domain?


Chronological Thread 
  • From: Jim Fox <>
  • To: Scott Cantor <>
  • Cc: "'Diego R. Lopez'" <>,
  • Subject: RE: Multiple targets in a single domain?
  • Date: Thu, 1 Jul 2004 09:51:17 -0700 (PDT)



On Thu, 1 Jul 2004, Scott Cantor wrote:


As far as the IP thing, we actually have almost no services at OSU that
disable the IP check. It comes up occasionally, but rarely. The firewall
issue is certainly true though, at least for users all grouped at one
location. Doesn't help the evil app either, since he's got a different
address.

Maybe we will add the ip check to pubcookie. It seems like a good idea. As far a the evil app goes however, it certainly is
helped if it is in cahoots with the evil coworker behind the
same firewall.

In any case, the security hole is smaller than I first thought.
It is more of a trust thing, as you said a long time ago.
Although I'd still advise not running a serious application on
a system where I didn't trust all the other users.

Jim



Archive powered by MHonArc 2.6.16.

Top of Page