SP/idp session still on after closing the browser with one application but not with other integrations
IAM David Bantz
dabantz at alaska.edu
Tue Oct 27 16:19:45 EDT 2015
On Tue, Oct 27, 2015 at 11:04 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> >However, with Mozilla Firefox 41, the sp and idp session still on even
> after closing the browser.
>
> Also dependent on settings, but very difficult to avoid with Firefox.
>
> That's how the web works now.
Yup. This combination of behavior of browsers and SSO session cookies seems
hard to explain to users, and leads to reasonable questions about how to
use web SSO safely. The old standby advice to "close your browser" when
finished isn't worth much and needs to be retired. But with what? I've
recommended that public computers require login and rebuild the system
image for a logout-login sequence, but is there something short of that we
can recommend?
David
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151027/0c0159ec/attachment.html>
More information about the users
mailing list