timeout settings

Lohr, Donald lohrda at jmu.edu
Thu Jun 20 12:34:17 EDT 2019


Thanks. See comments below.

Are local browser cookies for SSO, IdP and SP login created and used 
that contain active session/timeout values that could be misused?

On 6/20/19 11:47 AM, Cantor, Scott wrote:
> On 6/20/19, 11:05 AM, "users on behalf of Lohr, Donald" <users-bounces at shibboleth.net on behalf of lohrda at jmu.edu> wrote:
>
>> I am trying to get my head around how SP and IdP timeouts generally work and are generally configured.
> In most cases, whoever's asking doesn't know how to ask what they really want to know, and the usual answer to what they really need to know is "don't use shared machines, lock desktops, and move on".
Unfortunately, shared machines are a reality in our world with labs, 
kiosks, teaching computers in classrooms and at student staffed 
reception areas (to name the big ones).


-- 
D o n a l d   L o h r
  I n f o r m a t i o n   S y s t e m s
  J a m e s   M a d i s o n   U n i v e r s i t y
  5 4 0 . 5 6 8 . 3 7 3 0

  DOS:  Bad command or file name
  bash: command not found



More information about the users mailing list