Inconsistency in idp.session.timeout documentation?

Marvin Addison marvin.addison at gmail.com
Wed Nov 4 08:16:28 EST 2015


>
>   # IDP session must be at _least_ as long as authn result lifetime
>
> doesn't seem to line up with that interpretation. Why would a session
> inactivity setting need to necessarily be as long as the maximum lifetime
> of an authn result?


Good question. I believe that's a typo. I think it should be:

# IDP session must be at _least_ as long as authn result timeout


> Doesn't it just need to be as long as the longest authn result inactivity
> timeout that one wants to support?
>

I think you're right. I wrote those docs to document a very important
security policy area, but Scott's the authority on the design. I'll let him
comment before I update the docs.

M
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151104/98db3f91/attachment-0001.html>


More information about the users mailing list