Shibboleth session vs Application session

Cantor, Scott cantor.2 at osu.edu
Thu Dec 4 17:05:42 EST 2014


On 12/4/14, 9:59 PM, "Sathish Anickode" <SAnickode at skytouchtechnology.com> 
wrote:



>Yes. I meant the session at IdP end. Is there a way to call an API from 
>the SP end to extend the Idp session timeout each time any SP is 
>accessed? This is how the sessions behave when accessed within an 
>WebLogic container.

Absolutely not, and there is no single IdP session anyway. The only thing 
that matters at the IdP end is the amount of time that previous 
authentications will be reused, and that is not controllable by a timeout, 
they have a fixed lifetime set at the time they're created. The lifetime 
of that is controllable I believe, it should be in the wiki.

-- Scott



More information about the users mailing list