Single log out across all service providers

Cantor, Scott cantor.2 at osu.edu
Tue Aug 20 17:31:10 EDT 2013


On 8/20/13 4:26 PM, "Brian Reindel" <brian at reindel.com> wrote:

>We actually don't need to implement any front-channel or back-channel
>notifications for internal application session management because our
>IdP and all of our SPs are in the same security domain. We're going to
>end up deleting all domain cookies from the identity provider, which
>will in turn kill all sessions. I've tested in Firebug by removing all
>cookies after login, and it appears to be working.

I believe that is affected by browser definitions of third party cookies
and/or explicit configuration of SPs to use domain cookies instead of host
cookies, FWIW.

-- Scott




More information about the users mailing list