IDP Logout, text asking user whether or not to kill the IDP session

Cantor, Scott cantor.2 at osu.edu
Tue Oct 22 14:47:34 EDT 2013


On 10/22/13 12:57 PM, "Eric Goodman" <Eric.Goodman at ucop.edu> wrote:
>
>Dumb questions: how long does the SAML logout in the SP retain the
>knowledge of the source IdP? As long as the SP'a session?

As long as the session is still in the cache, it will return it for
logout, doesn't have to be valid any longer. There are many old settings
that influence that but the default now is to apply a basic slop offset on
top of the per-application timeout value to leave them in the cache for a
particular extra length of time.

> As long as the DS "which IdP do you use cookie"? I.e., if a user sits
>idle at an RP page long enough that the RP and SP session "dies", then
>clicks the "logout" link, will the SP still be able to redirect back to
>the correct IDP logout link?

Depends how long you sit.

-- Scott




More information about the users mailing list