Shibboleth session vs Application session

Sathish Anickode SAnickode at skytouchtechnology.com
Mon Dec 8 10:25:33 EST 2014


The following link (https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthnSession) states that the user will be forced to authenticate when the user session expires even though the authentication method lifetime has not exceeded.

If this is the case, can we set the user session expiration to 15 minutes and periodically refresh the session if the user is actively using an SP? 

-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Friday, December 05, 2014 12:58 PM
To: Shib Users
Subject: Re: Shibboleth session vs Application session

On 12/5/14, 6:51 PM, "Sathish Anickode" <SAnickode at skytouchtechnology.com>
wrote:

>The documentation states the following 
>(https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn). It 
>does mention that the statement is confusing.  Does that indicate that 
>the inactivity timeout is not supported?

That is not related to what you're asking about. That session has no connection to the SSO question, it can live forever without any security implications.

-- Scott

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list