different IDP session timeouts for different SPs?

Flannery, Sean sean.flannery at jwt.com
Wed Feb 11 13:05:45 EST 2015


Hello,

I think from the documentation this is not possible, but I wanted to verify: we have a request from one SP, that protects more sensitive data, to enforce a different session timeout at the IDP level, i.e. when that SP forwards users to the IDP it only respects sessions that started within the last 59 minutes, versus all the other SPs that have the default of 8 hours.  From what I'm seeing in the documentation, there is just one IDP session for all requests.

If that's correct, I'm supposing the best practice here is for this special SP to have the forceAuth flag set to true and apply its own sessions for only 1 hour, i.e. this SP is not part of the normal SSO contract since it considers itself special?  Does that sound right?

Sorry for the basic question.  Any help would be appreciated.

Sean

This transmission is intended solely for the person or organization to whom it is addressed and it may contain privileged and confidential information. If you are not the intended recipient you should not copy, distribute or take any action in reliance on it. If you believe you received this transmission in error please notify the sender.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150211/b82cf462/attachment.html 


More information about the users mailing list