Ticket #59 (closed enhancement: fixed)
Provide a configuration option for RPs to automatically reject unsolicited assertions
| Reported by: | http://blog.nerdbank.net/ | Owned by: | http://blog.nerdbank.net/ |
|---|---|---|---|
| Priority: | major | Milestone: | v3.2 RTW |
| Component: | OpenID | Version: | |
| Keywords: | Cc: |
Description
The government security profile may require that RPs reject unsolicited assertions. While RPs using DNOA today can already do that, we can help mitigate DoS attacks by skipping the check_auth step if it is determined that the incoming assertion was unsolicited anyway.
Change History
Note: See
TracTickets for help on using
tickets.
![(please configure the [header_logo] section in trac.ini)](http://nerdbank.org/RP/images/logo/dotnetopenid_tiny.gif)