Looks like the cookie causing problems (causing a user to be "remembered" when such isn't desired) is a JSESSIONID cookie, scoped to the External Authentication handler path. (The External Authn handler is what is being used in this case.) I am correct in my reading of the documentation that the authenticationDuration setting for a handler isn't supposed to matter if the PreviousSession handler is not activated -- is that indeed correct?

Which would presumably put the External Authn "trigger code" (filter/servlet) at fault for this cookie and its use.

