force termination of SSO session?
Peter Schober
peter.schober at univie.ac.at
Thu Jul 22 09:22:26 UTC 2021
* IAM David Bantz <dabantz at alaska.edu> [2021-07-22 02:02]:
> I’ve been asked whether it is possible to force immediate termination of a
> user’s Shibb SSO session as part of an incident response.
There's the account lockout feature:
https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1294074654/AccountLockoutManagement
(I'd expect this to prevent getting new assertions sent to any SPs.)
> (We realize that won’t do much for mischief in process in an SP session,
> but together with blocking authN might prevent a fire spreading.)
The Shib SP kind of supports administrative SAML logout using the session ID:
https://shibboleth.net/pipermail/users/2021-March/049400.html
-peter
More information about the users
mailing list