Administrative logout process

Cantor, Scott cantor.2 at osu.edu
Fri Jun 21 11:32:41 EDT 2019


It's not supported in any releases. The SOAP logout support added for V4 is the first prerequisite to ever implementing something at the IdP. No members have explicitly asked for it, though it's come up occasionally, and it will never be done without significant interest. The IdP can already implement sufficient authz logic to allow accounts to be blacklisted from use even if SSO would otherwise happen, so it's the SPs that matter anyway.
 
You can't address the SPs from the IdP alone. Few if any SPs support a form of logout that would allow for this to be dealt with by the IdP. As with most requests like this, these security people think the web works like a mainframe; it does not. SAML does not have a notion of revalidation of distributed sessions to detect anything like this.
 
-- Scott




More information about the users mailing list