SP timing out after 60 minutes.

Cantor, Scott cantor.2 at osu.edu
Wed Mar 27 13:03:33 EDT 2013


On 3/27/13 12:25 PM, "Ragadeep Sriperumbudur" <ragadeep99 at hotmail.com>
wrote:
>
>In a way its contradicting, but I can see the need where the IdP would
>want
>the user to authenticate each time before switching to an other
>application.

That has nothing to do with your SP or this setting, so they are
fundamentally confused.

>So take the below example
>
>- The client wants the user to go through the process of authentication
>(/let's assume Username/Pass authentication/) when the user switches from
>App-A to App-B

Your SP can't control that.

>Is there an alternative way to achieve the above without using
>SessionNotOnOrAfter?

There is no way to achieve it *with* that attribute in the first place.
Your SP's session has nothing to do with their IdP's session. Only they
can control that. Using ForceAuthn at all SPs would certainly achieve a
goal of sorts, but it requires everybody to be cooperating in a goal that
likely only they have. If they want a short SSO lifetime, they have that
choice. Nothing they do in a message to the SP will affect that.

-- Scott




More information about the users mailing list