IdP config parameter for the maximum time of a full authentication

Cantor, Scott cantor.2 at osu.edu
Mon Mar 18 11:00:18 EDT 2019


On 3/18/19, 10:36 AM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:

> Add the consent screen to the login process, and logins take a lot longer than they used to when they were only one UI
> screen long. I know one of the issues causing this is our SLB stickiness which is currently 5 minutes, and I plan to increase
> that. But it seems like the logins are encountering stale sessions in closer to three minutes.

Java timeout is 30 minutes by default. It's your load balancer.

> Can any of the IdP config params such as idp.policy.messageLifetime which we have set to the default of 3 minutes, also
> limit the amount of aitme that a user has to get through the login process?

No, nothing does but container session timeout.

-- Scott




More information about the users mailing list