Shibboleth session vs Application session
Cantor, Scott
cantor.2 at osu.edu
Fri Dec 5 12:59:09 EST 2014
On 12/5/14, 4:24 PM, "Sathish Anickode" <SAnickode at skytouchtechnology.com>
wrote:
>
>Based on the PCI requirements, I think it is fine if the IdP cookie has a
>life time of 8 hrs as long as the inactivity timeout is set to 15
>minutes. We would also configure the application sessions to timeout
>after 15 minutes of inactivity.
There is no inactivity timeout in the IdP. There is only authentication
method duration/lifetime applying individually to each login handler's
authentication result. It is a lifetime, not a timeout.
>In this scenario, if the user accesses a different application that uses
>the same SSO after 15 minutes, they will be forced to re-authenticate, as
>the IdP cookie would have expired due to inactivity. Is there a way to
>keep the IdP cookie from timing out due to inactivity while an
>application session is active?
There is no such timeout.
-- Scott
More information about the users
mailing list