Single Logout (SLO)

Cantor, Scott cantor.2 at osu.edu
Wed Jul 26 18:31:47 EDT 2017


On 7/26/17, 4:14 PM, "users on behalf of Muzinich, Mike" <users-bounces at shibboleth.net on behalf of MuziniM at losrios.edu> wrote:

> I reviewed what has been done on the My Buckeye Link page with the verbiage and Is this a private computer/device response
> handling.  A good model for everyone to follow.  Thanks for your help.

I don't know about good, but it's all I have at the moment.

I've discussed the "disable SSO" option for our public labs, but so far nobody here is interested so I haven't really explored what it would take. At a brute force level, there's a property for injecting a condition into the authentication flow beans in general-authn.xml that controls preservation of results. Depending on the scenario a script that checks the network range of the client may be enough to do most of the job.

But we have too many cross-SP business processes, so my guess is this is only ever going to be an option for a small set of cases, and it would probably end up simpler to just script something in my MFA logic to control things.

-- Scott




More information about the users mailing list