Skip links

Category: SAML

Apache Tomcat AJP Vulnerability

Apache Tomcat AJP Vulnerability

in Tags
Apache Tomcat is often used as the application server for CA SiteMinder Federation Services. On February 11th, 2020, the Ghostcat – Apache Tomcat AJP File Read/Inclusion Vulnerability (CNVD-2020-10487) was published (http://tomcat.apache.org/security-9.html). This vulnerability spanned multiple versions of Apache Tomcat. Apache Software Foundation recommended upgrading Apache
SiteMinder & AWS Cognito

SiteMinder & AWS Cognito

in Tags
Although Symantec SiteMinder runs in the cloud, some customers have elected to use AWS' Cognito (Cognito) as SAML Service Provider (SP) to authenticate users. This article will provide the steps necessary to configure SiteMinder to serve as the Identity Provider (IdP) between on premise enterprise