invalidating a session for a disabled user (Shibboleth SP)
Flannery, Sean
sean.flannery at jwt.com
Mon Mar 17 11:14:47 EDT 2014
Is there a best standard for invalidating a user's session manually? I'm
wondering how easy it is to support a situation where a user has been
disabled, i.e. removed from LDAP, and has an active SP session that
we want to immediately invalidate?
Most the documentation I'm finding seems to do with user-initiated logout
rather system-managed. My thought was, since the application that cares
about this level of access can query LDAP, that it (the downstream app)
just verify the user is still there, but there has been a request to
see if we can manage this above that app and force the user to lose his
SP session.
Any direction would be appreciated. Thanks for your time.
Sean
This transmission is intended solely for the person or organization to whom it is addressed and it may contain privileged and confidential information. If you are not the intended recipient you should not copy, distribute or take any action in reliance on it. If you believe you received this transmission in error please notify the sender.
More information about the users
mailing list