Backchannel Notify and NameID bound sessions
Cantor, Scott
cantor.2 at osu.edu
Sat Mar 3 13:47:34 GMT 2012
On 3/3/12 1:58 AM, "Harald Strack" <hstrack at ssystems.de> wrote:
>No, it doesn't send only on one single session. Actually it sends as
>much sessions as the user owns on this SP, here the SOAP Request from
>shibd.log (13 Sessions):
I would have to dig into the code to determine what it was supposed to do.
That might be right or wrong, I don't know. I'm headed out on vacation, so
I'll get into when I get back if you file a bug. The behavior should at
least be documented.
>Is this allowed in the schema?
Yes, and you can answer that yourself, the schema is in the SP install.
>That's the question: when only one <SessionID> Element is allowed, than
>it's correct otherwise not.
The schema is clear that it allows any number. That's separate from the
question of what it will do in any given scenario. If a logout comes in
from an IdP, then there are rules specifically covering what it has to do,
and in such cases, more than one session can get terminated.
>All Sessions belong to the same user. But only one of all these Sessions
>has been triggered for logout - the others share only the same NameID.
That sounds more like an external logout initiated by the IdP, not one
initiated by the SP. But I don't know, I'll get back to it later if you
file a reminder bug.
-- Scott
More information about the users
mailing list