Shibboleth session vs Application session
Sathish Anickode
SAnickode at skytouchtechnology.com
Thu Dec 4 15:27:08 EST 2014
I find that the shibboleth session and application session are distinct and each have their own time to live. However, I wanted to confirm if the life time for session tokens behave as follows:
Shibboleth session will live for a set duration while the application session, which also has a set duration, extends each time the application is accessed. However, Shibboleth sessions is not updated after each application access and does not extend beyond the preset expiration time.
As per PCI-DSS 3.0 standards, each application should have session timeout set to 15 minutes after which the user should be forced to authenticate again. Can you please let me know what would be the best practice for setting appropriate shibboleth session timeout to accomplish this requirement?
Thanks.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141204/26016c35/attachment-0001.html
More information about the users
mailing list