SP timing out after 60 minutes.
Peter Schober
peter.schober at univie.ac.at
Wed Mar 27 12:12:17 EDT 2013
* Ragadeep Sriperumbudur <ragadeep99 at hotmail.com> [2013-03-26 15:24]:
> We are in a similar situation, where the IdP is sending the
> "SessionNotOnOrAfter" value but wants us to ignore it.
* Ragadeep Sriperumbudur <ragadeep99 at hotmail.com> [2013-03-27 17:06]:
> The driving factor for the client to send that attribute is to have
> the principal authenticate against the IdP before going to the next
> SP application. So, they are setting a shorter span session for the
> user in the SessionNotOfAfter.
So (a) the IDP wants to limit the length the session at your SP.
And (b) it also wants to have longer sessions at your SP.
To me "(a) AND (b)" sounds not entirely unlike contradiction.
-peter
More information about the users
mailing list