shibboleth SP logout question
Cantor, Scott
cantor.2 at osu.edu
Thu Apr 25 12:19:22 EDT 2013
On 4/25/13 12:10 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>On 4/25/13 11:59 AM, "Sam Jacob" <skjacob at gmail.com> wrote:
>
>>after SP's "Shibboleth.sso/Logout", does the user have to close the
>>browser to enforce a logout?
>
>There is no fixed answer to that question, it depends on a host of
>factors. In many cases, closing the browser will have no additional effect
>anyway, and as I said, there is no single behavior invoked by that
>handler. It runs a set of logout initiators as configured and what the
>SAML2 handler does depends on the IdP and protocol. And none of that
>addresses the application session.
I can add, in response to that direct, isolated question, that if you're
talking about a standard Shibboleth IdP and SP, that there is absolutely
nothing done at the IdP when you run that handler. The IdP until 2.4 had
absolutely no features involving logout.
Assuming that the vast majority of IdPs do SSO, then obviously yes, the
user would have to close the browser. And that won't matter either, with
the most popular browsers.
-- Scott
More information about the users
mailing list