Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ax/SReg Params may be unsigned #64

Open
GoogleCodeExporter opened this issue Jul 6, 2015 · 0 comments
Open

Ax/SReg Params may be unsigned #64

GoogleCodeExporter opened this issue Jul 6, 2015 · 0 comments

Comments

@GoogleCodeExporter
Copy link

When user is returned form IdP (mode = id_res), a list of signed attributes and 
a signature is included. There is no guarantee that all attributes (ax 
attributes or sreg attributes) will be signed. This allows an attacker to 
assert attributes that are unsigned, and if the relying party uses them, they 
can be falsified.

For relying parties who need to have confidence in those items, there should be 
a way to tell which attributes are signed, or to only request attributes that 
are signed. Perhaps a flag to getAttributes($signedOnly = false);

I can work up a patch if you agree.

Original issue reported on code.google.com by [email protected] on 9 Apr 2013 at 2:57

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant