Single Logout (SLO)
Cantor, Scott
cantor.2 at osu.edu
Wed Jul 26 18:31:47 EDT 2017
On 7/26/17, 4:14 PM, "users on behalf of Muzinich, Mike" <users-bounces at shibboleth.net on behalf of MuziniM at losrios.edu> wrote:
> I reviewed what has been done on the My Buckeye Link page with the verbiage and Is this a private computer/device response
> handling. A good model for everyone to follow. Thanks for your help.
I don't know about good, but it's all I have at the moment.
I've discussed the "disable SSO" option for our public labs, but so far nobody here is interested so I haven't really explored what it would take. At a brute force level, there's a property for injecting a condition into the authentication flow beans in general-authn.xml that controls preservation of results. Depending on the scenario a script that checks the network range of the client may be enough to do most of the job.
But we have too many cross-SP business processes, so my guess is this is only ever going to be an option for a small set of cases, and it would probably end up simpler to just script something in my MFA logic to control things.
-- Scott
More information about the users
mailing list