Shibboleth session vs Application session

Cantor, Scott cantor.2 at osu.edu
Thu Dec 11 20:25:09 EST 2014


On 12/12/14, 1:20 AM, "Eric Goodman" <Eric.Goodman at ucop.edu> wrote:

>Or "what he said"...
>
>I'll note that while it might appear that Scott and I contradicted each 
>other in our last posts, the responses are actually in agreement with 
>each other. Scott's answer just assumes that you need the most 
>restrictive use case I described (which I can believe PCI DSS probably 
>implies) AND that you don't have absolute control over each SP and IdP of 
>interest.

I was specifically assuming multiple SPs and requiring a global inactivity 
timeout, and that's just not easily doable, and not at all with off the 
shelf code. The IdP has no idea when you last touched an SP, so no way to 
know what to do because of it.

-- Scott



More information about the users mailing list