Delete IdP User Sessions due to Security Incident Handling

Cantor, Scott cantor.2 at osu.edu
Wed Jun 4 09:53:43 EDT 2014


On 6/4/14, 9:08 AM, "Mike Wiseman" <mike.wiseman at utoronto.ca> wrote:

>There is some discussion in the security incident handling group about
>the need/desirability to delete idp sessions for a user by a security
>officer using a tool of some sort. Is this possible with shib?

No, it's not. When you factor in SLO in a global sense, then you reach the
conclusion that this is an impossible requirement if you're looking for
security guarantees, as opposed to best efforts, but speaking just in IdP
terms, no, we haven't exposed admin control over session state.

-- Scott




More information about the users mailing list