Differential Timeouts with like IdPs?
Michael Gettes
gettes at ufl.edu
Tue Jan 28 17:02:54 EST 2020
I would like to be able to have a default config for Idle Timeout (and maybe more, but this is a start for now) based on a combination of the user (what LDAP group(s) they may be a member of) and the application/SP they are accessing.
Scenario:
I access an SP-X via my IdP-Home and I receive a default session of 10H and an idle timeout of 10H.
I then go to access SP-AAL3 and because I am a user in ldap group AAL3 my IdP-Home sees
I am accessing SP-AAL3 and sets my idle timeout to 30M. This appears to not be possible now???
I realize I could have SP-AAL3 be bound to another IdP-AAL3 like my IdP-Home but with different
idle timeout config of 30M but this would involve an additional SSO sign-on - which would annoy my users.
But, if I configured IdP-AAL3 to be just like IdP-Home (same keys and crypto for cookies) and SP-AAL3 was
configured to only use IdP-AAL3 - would I not still get a SSO experience for my users without the
additional sign-on event? Would this get me an idle timeout to 30M going forward for all interactions with
SP-AAL3 and 10H for all SPs associated with IdP-Home? Has anyone done this?
I am trying to keep the scenario as simple as possible. If this is not possible right now, what would
It take to make this possible?
Thoughts and pontifications appreciated.
/mrg
More information about the users
mailing list