Backchannel Notify and NameID bound sessions

Chad La Joie lajoie at itumi.biz
Mon Mar 5 13:56:22 GMT 2012


The spec operates on a single session (nominally indexed by the
SessionIndex that appears in the logout request message).  When you
send a logout request you're requesting that that specific session be
destroyed.  Destroying some other session, which will have a different
SessionIndex, would be improper.

That said, none of that really affects admin-initiated logout.  In
such a situation you, the IdP admin, would just select the active
session you wanted to kill off and the IdP would end the appropriate
logout request to the applicable SPs.  A UI *may* be able to detect
that sessions 1, 2, and 3 were held by the same principal and offer a
way to terminate them all at once but under the hood the IdP would
still perform 3 separate SLO flows.

> You have made me curious. What part is against the spec? (The reason for
> asking is admin logout, where you probably can't avoid the multi-session
> problem.)
>
> Kristof
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list