Single Logout

Cantor, Scott cantor.2 at osu.edu
Mon Dec 1 10:19:40 EST 2014


On 12/1/14, 2:54 PM, "Ted Fisher" <tffishe at bgsu.edu> wrote:

> 
>But, we have an increasing number of outsourced applications over which 
>we have no control and often having an application session that persists 
>when the SP session has been ended.  This is making our global logout 
>attempt to fall more and more into the “even impossible” category.
> 
>How are others handling this kind of scenario?   
>Is the notion of SLO – particularly in a multi-vendor hodge-podge 
>non-homogenous mess of applications – truly altogether impossible as the 
>Shibboleth docs repeatedly imply? 

Well, we didn't say it because we were trolling people. It's the reality 
of the situation.

If you want a concrete suggestion, I'll make the same one I always make. 
Convince the browsers to fix it. One new cookie attribute (like HttpOnly, 
maybe call it Auth) and a button and we're done. They have the power to 
fix this, we don't.

Honestly, we should probably just build the browser add-on ourselves at 
this point (we can't do anything about the cookie attribute, but cookie 
clearing is good enough for shared machines, which is what this problem is 
really about).

-- Scott



More information about the users mailing list