v3 IdP SAML2 logout and external authentication with controlling session
Walter Forbes Hoehn (wassa)
wassa at memphis.edu
Mon Apr 20 10:28:36 EDT 2015
That is correct. The CAS protocol flows use the IdP session. Invalidating that session affects both SAML and CAS flows.
-Walter
> On Apr 20, 2015, at 8:55 AM, Scott Koranda <skoranda at gmail.com> wrote:
>
> P.S. It may be switching to using the v3 IdP for CAS in addition to
> SAML2 is a better solution and I will explore that too. I am assuming
> that a v3 response to a SAML2 logout request terminates *the* user
> session in that scenario and there is no separate "CAS session" to
> manage. That is, if the user's session with the IdP is terminated then
> any further new requests from either SAML2 SPs or CAS clients results
> in the user having to authenticate again (assuming vanilla
> username/password auth) at the IdP.
More information about the users
mailing list