force termination of SSO session?

Peter Schober peter.schober at univie.ac.at
Thu Jul 22 09:22:26 UTC 2021


* IAM David Bantz <dabantz at alaska.edu> [2021-07-22 02:02]:
> I’ve been asked whether it is possible to force immediate termination of a
> user’s Shibb SSO session as part of an incident response.

There's the account lockout feature:
https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1294074654/AccountLockoutManagement
(I'd expect this to prevent getting new assertions sent to any SPs.)

> (We realize that won’t do much for mischief in process in an SP session,
> but together with blocking authN might prevent a fire spreading.)

The Shib SP kind of supports administrative SAML logout using the session ID:
https://shibboleth.net/pipermail/users/2021-March/049400.html

-peter


More information about the users mailing list