Backchannel Notify and NameID bound sessions

Cantor, Scott cantor.2 at osu.edu
Sat Mar 3 13:47:34 GMT 2012


On 3/3/12 1:58 AM, "Harald Strack" <hstrack at ssystems.de> wrote:
>No, it doesn't send only on one single session. Actually it sends as
>much sessions as the user owns on this SP, here the SOAP Request from
>shibd.log (13 Sessions):

I would have to dig into the code to determine what it was supposed to do.
That might be right or wrong, I don't know. I'm headed out on vacation, so
I'll get into when I get back if you file a bug. The behavior should at
least be documented.

>Is this allowed in the schema?

Yes, and you can answer that yourself, the schema is in the SP install.

>That's the question: when only one <SessionID> Element is allowed, than
>it's correct otherwise not.

The schema is clear that it allows any number. That's separate from the
question of what it will do in any given scenario. If a logout comes in
from an IdP, then there are rules specifically covering what it has to do,
and in such cases, more than one session can get terminated.

>All Sessions belong to the same user. But only one of all these Sessions
>has been triggered for logout - the others share only the same NameID.

That sounds more like an external logout initiated by the IdP, not one
initiated by the SP. But I don't know, I'll get back to it later if you
file a reminder bug.

-- Scott




More information about the users mailing list