Logout

IAM David Bantz dabantz at alaska.edu
Thu Aug 13 16:49:44 UTC 2020


Some new (to my IdP) SPs invoke our IdP's Logout profile, killing the SSO
session.
That isn't necessarily the behavior the users want or expect - especially
if the Logout is called merely because of an application time-out. I
suppose I should try to get those SPs to change to a less impactful
behavior, but in the absence of that, I wonder about rewiring calls to the
Logout profile to allow the user the option to destroy the SSO session or
not; or even "just saying No" to destroying the SSO session. Have you dealt
with this situation? How does your IdP respond to SPs triggering 'global'
logout instead of just ending their SP session?

David Bantz
U Aalska
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200813/b878bad9/attachment.htm>


More information about the users mailing list