Shibboleth session vs Application session

Cantor, Scott cantor.2 at osu.edu
Fri Dec 5 12:59:09 EST 2014


On 12/5/14, 4:24 PM, "Sathish Anickode" <SAnickode at skytouchtechnology.com> 
wrote:


>
>Based on the PCI requirements, I think it is fine if the IdP cookie has a 
>life time of 8 hrs as long as the inactivity timeout is set to 15 
>minutes. We would also configure the application sessions to timeout 
>after 15 minutes of inactivity.

There is no inactivity timeout in the IdP. There is only authentication 
method duration/lifetime applying individually to each login handler's 
authentication result. It is a lifetime, not a timeout.

>In this scenario, if the user accesses a different application that uses 
>the same SSO after 15 minutes, they will be forced to re-authenticate, as 
>the IdP cookie would have expired due to inactivity. Is there a way to 
>keep the IdP cookie from timing out due to inactivity while an 
>application session is active?

There is no such timeout.

-- Scott



More information about the users mailing list