Shibboleth 3 idp session timeout configuration
Priyanshu Bhalotia
priyanshu.bhalotia at wooqer.com
Thu Oct 6 08:08:51 EDT 2016
hi all,
i have my shibboleth idp and my sp side configured and now i wanted to
setup the idp session settings and have gone through the official
documentation but wanted some more help on a few points.
idp.session.timeout is by default 60m..what security and resource issues
are most likely to happen when i increase the timeout to say 24h.
idp.authn.defaultlifetime=PT60M
idp.authn.defaultTimeout=PT30M
similarly what security and resource based problems am i most likely to
encounter on increasing the defualtlifetime to say 8hrs and defaultimeout
accordingly.
On a related topic, i also need clarification on the following problem,to
explain which lets take the following example:
If Suppose IDP is configured such that idp.authn.defaultTimeout is 60
minutes while the idp.authn.defaultLifetime is 120 min, SP session timeout
is 120 minutes. There is only activity at front channel at SP but no back
end channel activity. Then after 60 minutes,IDP timeout will occur due to
inactivity but SP session is still valid and then suppose SP redirects to
SP2 after 90 mins from initial login time which follows the same SSO
settings so it will then not get authenticated and get redirected to IDP
login page. How can i manage the session configuration so as to avoid such
conditions without compromising on security??
P.S. i have already referred to following links:
https://wiki.shibboleth.net/confluence/display/IDP30/SessionConfiguration
https://wiki.shibboleth.net/confluence/display/IDP30/Sessions
Thanks
--
Priyanshu Bhalotia
Platform Engineer
Wooqer
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161006/8f8c29ad/attachment-0001.html>
More information about the users
mailing list