shibboleth session management

samir el otmani elotmani.samir at gmail.com
Tue Feb 3 05:53:51 EST 2015


I need a workaround for this because it is required and important feature ,
is that the user will have only one active session , is there anyone who
can help me to perfom this workaround.

thank you

2015-01-29 14:57 GMT+00:00 Cantor, Scott <cantor.2 at osu.edu>:

> > 1)we want to use shibboleth only for authentification so we want to
> fully use
> > the application Session.
>
> You can only do that within limits. The SP session has to exist long
> enough for one resource request to a resource that establishes your
> application session. After that, you can do whatever you want.
>
> > 2) there will be no shibboleth session with same 'uid' in another words
> , we
> > have to maintain only one session for every uid connected (this is
> > implemented in application already using single sign out filter for CAS
> ).
>
> The SP doesn't support anything like that.
>
> > i have the following code in filter , so that it redirect to SP when
> there is no
> > shib-session-id , but i think this code is not sufficient because it's
> also rely on
> > the shib-session-id from Headers :
>
> I don't understand what you're asking, but in general checking for any of
> the built-in SP headers that are set for a session is an acceptable way to
> tell whether there's an SP session.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
*EL OTMANI Samir*
*Ingénieur d'Etat en Génie Informatique *
*Tel:+212 699 041 864*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150203/fd9635ef/attachment-0001.html 


More information about the users mailing list