shibboleth-dev - RE: Multiple targets in a single domain?
Subject: Shibboleth Developers
List archive
- From: Jim Fox <>
- To: Scott Cantor <>
- Cc: "'Diego R. Lopez'" <>,
- Subject: RE: Multiple targets in a single domain?
- Date: Thu, 1 Jul 2004 09:51:17 -0700 (PDT)
On Thu, 1 Jul 2004, Scott Cantor wrote:
As far as the IP thing, we actually have almost no services at OSU that
disable the IP check. It comes up occasionally, but rarely. The firewall
issue is certainly true though, at least for users all grouped at one
location. Doesn't help the evil app either, since he's got a different
address.
Maybe we will add the ip check to pubcookie. It seems like a good idea. As far a the evil app goes however, it certainly is
helped if it is in cahoots with the evil coworker behind the
same firewall.
In any case, the security hole is smaller than I first thought.
It is more of a trust thing, as you said a long time ago.
Although I'd still advise not running a serious application on
a system where I didn't trust all the other users.
Jim
- Re: Multiple targets in a single domain?, Diego R. Lopez, 07/01/2004
- RE: Multiple targets in a single domain?, Scott Cantor, 07/01/2004
- RE: Multiple targets in a single domain?, Jim Fox, 07/01/2004
- RE: Multiple targets in a single domain?, Scott Cantor, 07/01/2004
- RE: Multiple targets in a single domain?, Jim Fox, 07/01/2004
- RE: Multiple targets in a single domain?, Scott Cantor, 07/01/2004
- RE: Multiple targets in a single domain?, Paul B. Hill, 07/01/2004
- RE: Multiple targets in a single domain?, Scott Cantor, 07/01/2004
- Re: Multiple targets in a single domain?, Michael A. Grady, 07/01/2004
- Re: Multiple targets in a single domain?, Jim Fox, 07/01/2004
- RE: Multiple targets in a single domain?, Scott Cantor, 07/01/2004
- RE: Multiple targets in a single domain?, Jim Fox, 07/01/2004
- RE: Multiple targets in a single domain?, Scott Cantor, 07/01/2004
- RE: Multiple targets in a single domain?, Jim Fox, 07/01/2004
- RE: Multiple targets in a single domain?, Scott Cantor, 07/01/2004
Archive powered by MHonArc 2.6.16.