Backchannel Notify and NameID bound sessions
Kristof Bajnok
bajnokk at niif.hu
Mon Mar 5 13:22:24 GMT 2012
On 05/03/12 12:23, Chad La Joie wrote:
> No, v3 will only destroy the session associated with given logout request..
I think this is the answer to the OP.
Probably an RFE could help keeping track of this limitation, but I can
agree with the Shib devs that your multiple IdP sessions + shared nameid
+ SLO scenario is quite special, and concerning the fundamental changes
it seems to require, it will probably get low priority.
> On Mon, Mar 5, 2012 at 06:09, Kristof Bajnok <bajnokk at niif.hu> wrote:
>> The problem is that currently it's not possible to clear _all_ IdP
>> sessions at the IdP. Still I'm wondering how the process should be done.
>> How can one user's IdP sessions be bound together? I suspect, the
>> principal name might be different across sessions (it's bound to the
>> authentication), but is there any other key for this purpose? Will this
>> be possible with v3?
>
Kristof
More information about the users
mailing list