force termination of SSO session?
Peter Schober
peter.schober at univie.ac.at
Fri Jul 23 07:16:37 UTC 2021
* Cantor, Scott <cantor.2 at osu.edu> [2021-07-22 14:15]:
> On 7/22/21, 5:22 AM, "users on behalf of Peter Schober" <users-bounces at shibboleth.net on behalf of peter.schober at univie.ac.at> wrote:
>
> > There's the account lockout feature:
> > (I'd expect this to prevent getting new assertions sent to any SPs.)
>
> It does not, that's authentication only.
Would it be possible to have the authn subsystem(s) check back with
the account lockout status in a future release before succeeding?
Or would that mess up thr design somehow?
(And of course I have no idea how big of a change that would be.)
-peter
More information about the users
mailing list