SP timing out after 60 minutes.

Ragadeep Sriperumbudur ragadeep99 at hotmail.com
Wed Mar 27 14:28:17 EDT 2013


Cantor, Scott E. wrote
> If they want a short SSO lifetime, they have that
> choice. Nothing they do in a message to the SP will affect that.

I understand each IdP is different, but for the sake of discussion - is
there a way to define a shorter user session in the Shibboleth IdP and not
send the /SessionNotOnOrAfter /attribute in the SAML response to the SP. We
currently use Shibboleth Idp for internal testing of our SP and know about
the /maximumSPSessionLifetime/property on the profile configuration to use.
But that attribute directly controls the SessionNotOnOrAfter property in
SAML response.

I also came across the usage of an /AuthnStatement / in the profile
specification. The profile spec states below

      If an <AuthnStatement> used to establish a security context for
      the principal contains a SessionNotOnOrAfter XML attribute, the
      security context SHOULD be discarded once this time is reached,
      /*unless the service provider reestablishes the principal's identity
      by repeating the use of this profile*/. 

I also came across the following thread from 2009 where Scott replied that
Shibboleth SP currently does not have the capability. 
Shibboleth-Service-Provider-Premature-Session-Removal
<http://shibboleth.1660669.n2.nabble.com/Shibboleth-Service-Provider-Premature-Session-Removal-td3657824.html>  

Has anything changed since then? Does Shibboleth SP offer this now? 

Our interpretation of the profile spec of the /AuthnStatement / and
specifically in reference to the last part where the SP reestablishes the
principal's identity would mean that the SP will have to create new sessions
with the specified session expiry as long as the assertion from the IdP is
valid.





--
View this message in context: http://shibboleth.1660669.n2.nabble.com/SP-timing-out-after-60-minutes-tp7584660p7585712.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list