Shibboleth session vs Application session
Sathish Anickode
SAnickode at skytouchtechnology.com
Thu Dec 4 16:59:53 EST 2014
Yes. I meant the session at IdP end. Is there a way to call an API from the SP end to extend the Idp session timeout each time any SP is accessed? This is how the sessions behave when accessed within an WebLogic container.
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Thursday, December 04, 2014 2:39 PM
To: Shib Users
Subject: Re: Shibboleth session vs Application session
On 12/4/14, 9:23 PM, "Sathish Anickode" <SAnickode at skytouchtechnology.com>
wrote:
>Thanks for your reply. I wanted to additionally clarify the following:
>
>We are planning to use WebLogic SAML integration. Additionally, since our
>existing application uses container sessions extensively, we will be
>using our application session instead of the Shibboleth session.
As Kevin said, then there is no Shibboleth session if you're not using the
Shibboleth software.
Unless you mean the IdP, but that's much more complicated, now you're
talking about SSO and those implications. That doesn't comport with any
kind of control at the SP end. If you need that kind of control, you have
to use ForceAuthn, and open that can of worms (cue Eric), or it doesn't
matter what you do at the SP end.
With respect to the PCI statement, that is fundamentally at odds with SSO
because it assumes that a timeout at the application end guarantees the
ability to "force" reauthentication. So again, that's ForceAuthn, and few
IdPs are going to give you that with any reliability.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list