shibboleth-dev - RE: Shibboleth and ipv6
Subject: Shibboleth Developers
List archive
- From: "Scott Cantor" <>
- To: <>
- Subject: RE: Shibboleth and ipv6
- Date: Tue, 18 Oct 2005 11:39:37 -0400
- Organization: The Ohio State University
> What then happens is (User = User's web browser):
> 1. Users connects to SP using ipv4 ip
> 3. User connects to IdP using ipv6 ip
> 6. User connects to SP using ipv4 ip
> 7. SP checks handle and throws an error because the ipv6 IP in the
> handle is not the same as the ipv4 IP that was used to
> connect to the SP
Ok...but that's not really fixable unless you do some kind of NAT process at
the IdP. I think somebody actually wrote some code to do that, although I
think at the time I was pretty confused about the purpose. I guess I sort of
get it now.
> There wouldn't be a problem if SP or IdP somehow could figure out what
> ipv4 and an ipv6 IP the user has. Unfortunately this is probably not
> easy or not possible at all. The only way I know may work is to do a
> reverse dns lookup to the the hostname of the user and then do a dns
> lookup for ipv4 or ipv6...
Well, if somebody think's that's actually possible, they're welcome to
supply a patch. It's definitely not a priority for me.
> So, I would say the only option is to disable the address checking in
> that situation.
So would I. And that's not really uncommon. I think you can make the case
that all SSO systems are insecure without address checking, and that
unfortunately leads to some bad conclusions.
-- Scott
- Shibboleth and ipv6, Lukas Haemmerle, 10/14/2005
- RE: Shibboleth and ipv6, Scott Cantor, 10/14/2005
- Re: Shibboleth and ipv6, Lukas Haemmerle, 10/18/2005
- Re: Shibboleth and ipv6, Spencer W. Thomas, 10/18/2005
- Re: Shibboleth and ipv6, Lukas Haemmerle, 10/18/2005
- RE: Shibboleth and ipv6, Scott Cantor, 10/18/2005
- RE: Shibboleth and ipv6, RL 'Bob' Morgan, 10/19/2005
- RE: Shibboleth and ipv6, Scott Cantor, 10/19/2005
- RE: Shibboleth and ipv6, Scott Cantor, 10/19/2005
- RE: Shibboleth and ipv6, RL 'Bob' Morgan, 10/19/2005
- RE: Shibboleth and ipv6, Scott Cantor, 10/19/2005
- Re: Shibboleth and ipv6, Ian Young, 10/20/2005
- Re: Shibboleth and ipv6, RL 'Bob' Morgan, 10/20/2005
- RE: Shibboleth and ipv6, Scott Cantor, 10/19/2005
- RE: Shibboleth and ipv6, RL 'Bob' Morgan, 10/19/2005
- Re: Shibboleth and ipv6, Spencer W. Thomas, 10/18/2005
- Re: Shibboleth and ipv6, Lukas Haemmerle, 10/18/2005
- RE: Shibboleth and ipv6, Scott Cantor, 10/14/2005
Archive powered by MHonArc 2.6.16.