Shibboleth session vs Application session
Cantor, Scott
cantor.2 at osu.edu
Thu Dec 11 20:25:09 EST 2014
On 12/12/14, 1:20 AM, "Eric Goodman" <Eric.Goodman at ucop.edu> wrote:
>Or "what he said"...
>
>I'll note that while it might appear that Scott and I contradicted each
>other in our last posts, the responses are actually in agreement with
>each other. Scott's answer just assumes that you need the most
>restrictive use case I described (which I can believe PCI DSS probably
>implies) AND that you don't have absolute control over each SP and IdP of
>interest.
I was specifically assuming multiple SPs and requiring a global inactivity
timeout, and that's just not easily doable, and not at all with off the
shelf code. The IdP has no idea when you last touched an SP, so no way to
know what to do because of it.
-- Scott
More information about the users
mailing list