Delete IdP User Sessions due to Security Incident Handling
Cantor, Scott
cantor.2 at osu.edu
Wed Jun 4 09:53:43 EDT 2014
On 6/4/14, 9:08 AM, "Mike Wiseman" <mike.wiseman at utoronto.ca> wrote:
>There is some discussion in the security incident handling group about
>the need/desirability to delete idp sessions for a user by a security
>officer using a tool of some sort. Is this possible with shib?
No, it's not. When you factor in SLO in a global sense, then you reach the
conclusion that this is an impossible requirement if you're looking for
security guarantees, as opposed to best efforts, but speaking just in IdP
terms, no, we haven't exposed admin control over session state.
-- Scott
More information about the users
mailing list