Shibboleth session vs Application session
Cantor, Scott
cantor.2 at osu.edu
Thu Dec 4 17:05:42 EST 2014
On 12/4/14, 9:59 PM, "Sathish Anickode" <SAnickode at skytouchtechnology.com>
wrote:
>Yes. I meant the session at IdP end. Is there a way to call an API from
>the SP end to extend the Idp session timeout each time any SP is
>accessed? This is how the sessions behave when accessed within an
>WebLogic container.
Absolutely not, and there is no single IdP session anyway. The only thing
that matters at the IdP end is the amount of time that previous
authentications will be reused, and that is not controllable by a timeout,
they have a fixed lifetime set at the time they're created. The lifetime
of that is controllable I believe, it should be in the wiki.
-- Scott
More information about the users
mailing list