shibboleth-dev - RE: [Shib-Dev] [IdPv3] Security Config and Options
Subject: Shibboleth Developers
List archive
- From: "Scott Cantor" <>
- To: <>
- Subject: RE: [Shib-Dev] [IdPv3] Security Config and Options
- Date: Fri, 6 Aug 2010 12:20:29 -0400
- Organization: The Ohio State University
> However, according to this reasoning (DOS prevention) the SP's default
> configuration then also should have turned off Artifact support because
> otherwise it is very easy to make the SP do an attribute query to just
> any IdP it has metadata for, thanks to the artifact profile :-)
I don't think it's quite as bad. Assuming SSL handshakes are as bad, which
I'm not sure about (and if they were, couldn't you just DOS the site by
slamming it with SSL requests?), the SP caches and reuses HTTP and SSL
sessions with IdPs.
Honestly, the DOS thing is probably a bit overstated. I suspect that's so
trivial with any web site that adding another vector to use isn't much
worse.
-- Scott
- Re: [Shib-Dev] [IdPv3] Security Config and Options, (continued)
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Chad La Joie, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Chad La Joie, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Chad La Joie, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Chad La Joie, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Peter Schober, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- RE: [Shib-Dev] [IdPv3] Security Config and Options, Scott Cantor, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Chad La Joie, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Etienne Dysli, 08/19/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Chad La Joie, 08/19/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
Archive powered by MHonArc 2.6.16.