Delete IdP User Sessions due to Security Incident Handling
Peter Schober
peter.schober at univie.ac.at
Wed Jun 4 09:40:50 EDT 2014
* Mike Wiseman <mike.wiseman at utoronto.ca> [2014-06-04 15:09]:
> There is some discussion in the security incident handling group
> about the need/desirability to delete idp sessions for a user by a
> security officer using a tool of some sort. Is this possible with
> shib? I've looked at the idpEnableSSO page but the focus, of course,
> is on self logout.
I guess they don't just want to disable the subject's session cookie
with the IDP (giving her "SSO"), they will also want to terminate
sessions on all SPs the subject accessed?
So no, there is no SLO support in the Shib IDP today, and that
includes "administrative SLO" when the subject is not present.
-peter
More information about the users
mailing list