What is the Shibboleth alternative to a logout function?

Paul Hethmon paul.hethmon at clareitysecurity.com
Tue Dec 20 20:23:52 GMT 2011


Tell the user to close the browser.


On 12/20/11 3:19 PM, "Jason Holland" <jholland at olp.net> wrote:

>I'm trying to figure out what the best practices are regarding security
>when managing a federation that uses a Shibboleth IdP.
>
>Since Shibboleth doesn't support SLO how does a user end their SSO
>session if they were logged into a Service Provider that had sensitive
>data? Or in other words how should a Service Provider behave in order to
>protect sensitive data when the user is done?
>
>Thanks,
>Jason
>
>-----Original Message-----
>From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net]
>On Behalf Of Chad La Joie
>Sent: Tuesday, December 20, 2011 11:33 AM
>To: Shib Users
>Subject: Re: Documentation for SingleLogoutService to a Shib IdP?
>
>The IdP doesn't support SLO because in most cases it doesn't work.
>You can read about here:
>https://wiki.shibboleth.net/confluence/display/SHIB2/SLOIssues
>
>On Tue, Dec 20, 2011 at 12:24, Jason Holland <jholland at olp.net> wrote:
>> I am trying to setup SingleLogoutService with a Shibboleth IdP and a
>> simpleSAMLphp SP. In simpleSAMLphp there is a setting where you enter
>> the IdP's URL for the IdP's SingleLogoutService. I can't find how to
>> set this up on my Shibboleth IdP in the documentation as I can only
>> find where Shibboleth supports SingleLogout as a Service Provider, any
>hints?
>>
>>
>>
>> Thanks!
>>
>> Jason
>>
>>
>> --
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>
>
>
>--
>Chad La Joie
>www.itumi.biz
>trusted identities, delivered
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net
>
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net



More information about the users mailing list