Inconsistency in idp.session.timeout documentation?
Marvin Addison
marvin.addison at gmail.com
Wed Nov 4 08:16:28 EST 2015
>
> # IDP session must be at _least_ as long as authn result lifetime
>
> doesn't seem to line up with that interpretation. Why would a session
> inactivity setting need to necessarily be as long as the maximum lifetime
> of an authn result?
Good question. I believe that's a typo. I think it should be:
# IDP session must be at _least_ as long as authn result timeout
> Doesn't it just need to be as long as the longest authn result inactivity
> timeout that one wants to support?
>
I think you're right. I wrote those docs to document a very important
security policy area, but Scott's the authority on the design. I'll let him
comment before I update the docs.
M
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151104/98db3f91/attachment-0001.html>
More information about the users
mailing list