Backchannel Notify and NameID bound sessions
Chad La Joie
lajoie at itumi.biz
Mon Mar 5 13:56:22 GMT 2012
The spec operates on a single session (nominally indexed by the
SessionIndex that appears in the logout request message). When you
send a logout request you're requesting that that specific session be
destroyed. Destroying some other session, which will have a different
SessionIndex, would be improper.
That said, none of that really affects admin-initiated logout. In
such a situation you, the IdP admin, would just select the active
session you wanted to kill off and the IdP would end the appropriate
logout request to the applicable SPs. A UI *may* be able to detect
that sessions 1, 2, and 3 were held by the same principal and offer a
way to terminate them all at once but under the hood the IdP would
still perform 3 separate SLO flows.
> You have made me curious. What part is against the spec? (The reason for
> asking is admin logout, where you probably can't avoid the multi-session
> problem.)
>
> Kristof
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
More information about the users
mailing list