Different SSO session timeouts based on IP
Aaron Howell
aaron.howell at deakin.edu.au
Mon Jul 18 16:27:48 EDT 2016
I'm about to have a meeting with management. What they are asking - I don't think is the solution to pursue - but I had better address their questions with facts.
We have some "kiosk" machines that are always logged in. People are using Shibboleth protected sites on them and forgetting to close the browser or logout.
Is there a way to apply different SSO session limits at the IdP based on IP address? (or as they are domain joined - machine name)
Or another recommended Shibboleth option to pursue?
Personally I think they are trying to address the issue at the wrong location - and should actually address the insecure-by-design kiosks - but currently that suggestion is considered too much work.
Cheers,
Aaron
Important Notice: The contents of this email are intended solely for the named addressee and are confidential; any unauthorised use, reproduction or storage of the contents is expressly prohibited. If you have received this email in error, please delete it and any attachments immediately and advise the sender by return email or telephone.
Deakin University does not warrant that this email and any attachments are error or virus free.
More information about the users
mailing list