Google apps logout script breaks under Tomcat 8?
Michael A Grady
mgrady at unicon.net
Fri Mar 20 21:23:00 EDT 2015
On Mar 20, 2015, at 4:37 PM, Cantor, Scott <cantor.2 at OSU.EDU> wrote:
> On 3/20/15, 4:52 PM, "Baron Fujimoto" <baron at hawaii.edu> wrote:
>>
>> Sorry, via CAS3, based on documentation here:
>> <https://wiki.jasig.org/display/CASUM/Shibboleth-CAS+Integration>
>
> Ok, but in what way would clearing those cookies have any impact on logout? I'm just not seeing it. The IdP's session won't matter. Even if you cleared the JSESSIONID cookie, and even if that were the basis of the CAS session, all that would do is take you back to CAS and you'd be right back in again.
>
> Maybe the script you were using also was doing a CAS logout, but if that's the case, it shouldn't matter what happens with the IdP. You could just turn off the PreviousSession handler and push all the SSO aspects back to CAS.
>
Yes, whenever I work with someone layering the IdP over CAS, I recommend disabling PreviousSession on the IdP, because then you have no session there you need to logout of -- you just send the user to the CAS logout endpoint.
--
Michael A. Grady
Senior IAM Consultant, Unicon, Inc.
More information about the users
mailing list