SP prompting for persistent id expiration?
Liam Hoekenga
liamr at umich.edu
Mon Nov 14 09:37:39 EST 2016
One of our units on campus has set up their instance of NetIQ Access
Manager to proxy authn requests to our IDP (Access Manager would normally
be an IDP).
Apparently, Access Manager has a concept of "defederation":
If you have configured the Identity Server to be a service provider
and have established a trusted relationship with one or more identity
providers, the cards of these trusted identity providers appear in the
Authentication Cards section. Your users can use the identity provider’s
authentication card to federate their account at the identity provider
with
their account at the service provider. When they federate an account,
they
are telling the service provider to trust the authentication
established at the
identity provider. This enables single sign-on between the providers.
The
card can also be used to defederate the accounts. On the authentication
card,
click Card Options, then select Defederate.
The team running this server expects the act of "defederation" in thier
application to contact the our IDP and expire the given user's persistent
ID.
The feels awfully vendor specific. Is this a standard SAML thing?
Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161114/79e5d284/attachment.html>
More information about the users
mailing list