shibboleth-dev - Fwd: Form Login
Subject: Shibboleth Developers
List archive
- From: Nate Klingenstein <>
- To:
- Cc: Steven Carmody <>, Velpi - GroupT <>
- Subject: Fwd: Form Login
- Date: Tue, 8 Mar 2005 00:45:55 +0000
smells like a contribution...
Begin forwarded message:
I also built a 'filter' for Tomcat which gives some extra protection for
the 'RemoteUser' value. It will eliminate most of the session-hijacking
attempts that will ever occur by invalidating the session (and thus the
logged-in state) when there is doubt about the user's identity. This is
done by 'remembering' and checking some HTTP headers (configurable by
xml) of the user that owns the session. I'd be happy to give that to the
community too. At the moment the filter is going into alpha phase so I
probably still have to take off some sharp edges.
- Fwd: Form Login, Nate Klingenstein, 03/07/2005
Archive powered by MHonArc 2.6.16.