Question on Sp logout redirect control

Ewing, Bill BEwing at utsystem.edu
Fri Dec 2 16:42:33 EST 2016


Scott,

Thanks for the response. Here was my initial attempt at adding the settings which didn’t seem to block anything. See anything glaringly obvious in my syntax or am I not in the right ballpark?

<Sessions lifetime="28800" timeout="3600" relayState="ss:mem"
                  checkAddress="false" handlerSSL="false" cookieProps="http" redirectLimit="host+whitelist" redirectWhitelist="scheme://example.com[:443]/">

Thanks,
Bill

-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Friday, December 02, 2016 2:03 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: Question on Sp logout redirect control

On 12/2/16, 2:56 PM, "users on behalf of Ewing, Bill" <users-bounces at shibboleth.net on behalf of BEwing at utsystem.edu> wrote:

> I haven’t been able to find out how to control/limit that behavior to 
> only allow specific redirect urls on logout to avoid emails that we are phishing folks.

https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessions

redirectLimit
redirectWhitelist

-- Scott
 

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list