Deleting application cookie on shib sp session creation?

Ian Rifkin irifkin at brandeis.edu
Mon Jan 22 14:00:01 EST 2018


Hello,

We use Shib IdP successfully both with vendors and with our own Shib SP
instances.

One of our newer Shib SP instances is basically a proxy server for a
specific application. Login works fine and logout works as expected. The
tricky part is application session expiration.

If the application session cookie is valid it doesn't matter who you SSO as
since the application won't look at the user from SSO. Worse, there are
situations where the application session cookie is "old" but instead of
showing an expired session page or logging the person in, it displays an
undesired error page.

It's an application issue, but I'm wondering if there's anything I can do
on the Shib SP side of things. Is it possible on the Shib SP side that on a
new SP session it will delete a specific (non-Shib) application cookie as
part of the SSO process?

Thanks,
Ian

-- 
*Ian Rifkin '04, MS '09*
Director of Data and Systems Integration
Brandeis University, Information Technology Services (ITS)
Email: irifkin at brandeis.edu | Phone: (781) 736-4216 | Fax: (781) 736-4577
Learn more about our campus move to Workday
<http://www.brandeis.edu/workday/>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180122/5223d430/attachment.html>


More information about the users mailing list