Questions about SLO support in IdP 2.4.0

Yaowen Tu yaowen.tu at gmail.com
Fri Apr 19 16:07:57 EDT 2013


Hi,

First of all thanks to everyone who worked on the 2.4.0 release, good work.

I am reading
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableSLO about the
SLO support in 2.4.0, and have some questions.

1. Just to double confirm that IdP will terminate the session associated
with the SP that send the logout request, and leave other SPs unchanged.
How about the following scenario:
          a. In one browser, I logged in as user1 for SP1 and SP2.
          b. I click logout from SP1. New user1 in SP1 is logged out, but
user1 in SP2 still loggs in, right?
          c. What if I try to access SP1 in the same browser, will IdP
prompt login screen? I guess yes, then can I login as a different user same
user2 for SP1?
          d. In the end, in one browser, user2 logged in SP1, and user2
logged in SP2, is that correct?

2. In Local logout section, I see "a direct non-SAML request", can you tell
me what kind of request is that?

3. I am still not very clear what's different between Local and SAML logout
in terms of session management on IdP side, I know that in SAML logout, it
will terminate the session associated with this SP, and how about Local
logout? I see "the IdP locates an active session based on the client's
cookie and terminates it.", but what are the differences between these two
sessions?

Please correct me if there is any misunderstanding.


Thanks,
Yaowen
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130419/0a33269e/attachment.html 


More information about the users mailing list