SAML Logout -- giving users options .....

Kristof Bajnok bajnokk at niif.hu
Wed Sep 12 01:32:09 EDT 2012


Hi Steven,

On 09/11/2012 10:14 PM, Steven Carmody wrote:
> 2) In addition, the Application could request that the Shib SP redirect 
> the user to a specific url at the IDP associated with the Shib session. 
> This endpoint could do some combination of actions:
> 
> a) tell the user to quit their browser (no longer a good idea with 
> Firefox...). Don't do anything further ....
> 
> b) destroy the IDP session. The user will have to re-authenticate the 
> next time they attempt to access a Shib-protected application. We are 
> now doing this for some Applications (eg our HR system).
> 
> c) Ask the user whether or not they want to destroy the IDP session.
> 
> This last option appeals to me, but no one here has yet developed a 
> design or text that could help a "regular user" make an informed decision.

Unfortunately neither of the above is SAML Logout.

The IdP SLO build asks the user whether to try to logout from all SPs or
just from the IdP, but it will destroy the IdP session anyway.

Kristof


More information about the users mailing list