shibboleth SP logout question

Cantor, Scott cantor.2 at osu.edu
Thu Apr 25 12:10:26 EDT 2013


On 4/25/13 11:59 AM, "Sam Jacob" <skjacob at gmail.com> wrote:

>after SP's   "Shibboleth.sso/Logout", does the user have to close the
>browser to enforce a logout?

There is no fixed answer to that question, it depends on a host of
factors. In many cases, closing the browser will have no additional effect
anyway, and as I said, there is no single behavior invoked by that
handler. It runs a set of logout initiators as configured and what the
SAML2 handler does depends on the IdP and protocol. And none of that
addresses the application session.

If you want a short answer, logout doesn't work at scale and it never will
unless the browser vendors cooperate and just do it themselves. So you
could assume that closing the browser is the only option and that still
requires clearing cookies on Chrome or Firefox.

If you want certainty, that's the only assumption that is likely to be
accurate.

-- Scott




More information about the users mailing list