Shibboleth-SP handling of long delay in user logging in with IdP
Stockley, Jonathan
jonathan.stockley at emc.com
Mon Jul 7 20:29:09 EDT 2014
Hi,
We are using Shibboleth-SP 2.5.2 with MS AD/ADFS/ADFS-Proxy as the IdP. Shibboleth redirects the browser to the ADFS Proxy (IIS running customization .Net app) which presents a login page. All works very well, except when the user decides to go to lunch and leaves the login page displayed. When they return and complete the login, the browsers gets redirected back to Shibboleth-SP and a POST of the SAML Claims is sent. At this point the user is shown the default index.html of from the Apache web server that is hosting Shibboleth-SP.
I'm assuming that the Shibboleth-SP session is timing out, we have session lifetime set to 8 hours and timeout set to 10 minutes.
1. If I set session timeout to 0 will the user be able to log in up to the session lifetime?
2. Is there any way to handle this differently, like redirect to some URL?
Thanks,
Jo
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140707/8d4aa252/attachment.html
More information about the users
mailing list