Possibility to revoke sessions when using client storage

Cantor, Scott cantor.2 at osu.edu
Mon Apr 2 12:12:46 EDT 2018


> I was just having this same thought when I read your previous message.  Do
> we actually need SAML Logout (propagated to SPs) or just the ability to
> prevent future re-use of the SSO session?

I think it's extremely limiting to think in terms of the IdP alone, borderline irresponsible in some sense, but I recognize that that's not a shared view, but...
 
  The solution above is more akin to
> User Lockout because it would be an on-going block, not just destruction of
> the existing SSO session.

No, I was presuming something timestamp based, i.e. any sessions created prior to time X would be deemed unusable. But that can become "locked" if you just set the time to a future date.

-- Scott



More information about the users mailing list