IDP session timeout
Rainer Hoerbe
rainer at hoerbe.at
Tue Nov 15 11:04:14 EST 2016
Virajitha,
This use case was discussed in the Kantara eGov WG some years ago:
https://kantarainitiative.org/confluence/display/eGov/IDP+idle+timeout+management+using+session+refresh+via+isPassive <https://kantarainitiative.org/confluence/display/eGov/IDP+idle+timeout+management+using+session+refresh+via+isPassive>
Sending AuthnRequests with isPassive was reported to have been in used in Finnland. IIRC it was a government deployment and did work for certain IDPs, but not universally.
Are you able to enforce that your deployments support deep linking and POST preservation? If so, shortening the SP timeout should do the trick.
- Rainer
> Am 14.11.2016 um 18:36 schrieb Cantor, Scott <cantor.2 at osu.edu>:
>
>> I was looking at the logoutconfigurations, SessionConfiguration,
>> StorageConfiguration @wiki.shibboleth.net. But couldnot find any
>> information on the concerned issue. It would be helpful if you could just read the
>> content of my last post and let me know if shibboleth is giving any support
>> or not.
>
> No.
>
> What you want does not exist interoperably across SAML implementations.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161115/8224b7d3/attachment-0001.html>
More information about the users
mailing list