SLO in shiboleth
Stefan Rasmusson
rasmusson.stefan at gmail.com
Mon Jan 20 07:26:35 EST 2014
I'm reading up on the SLO capabillitites of Shiboleth. On
https://wiki.shibboleth.net/confluence/display/SHIB2/SLOIssues it says
"The easiest is to remove all application level session management and rely
solely on the Shibboleth SP's session management"
Is it correct to assume that this sessionmanagement only refers to
authenticated session managament. The application should not use the
appliation session to validate that a user is authenticated.
But its ok to store other information on the application session, right?
If we do this and use backchannel SLO, would it be correct to assume that
the SLO will work good?
--
Stefan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140120/63fc9467/attachment.html
More information about the users
mailing list