force termination of SSO session?

Peter Schober peter.schober at univie.ac.at
Fri Jul 23 07:16:37 UTC 2021


* Cantor, Scott <cantor.2 at osu.edu> [2021-07-22 14:15]:
> On 7/22/21, 5:22 AM, "users on behalf of Peter Schober" <users-bounces at shibboleth.net on behalf of peter.schober at univie.ac.at> wrote:
> 
> >    There's the account lockout feature:    
> >    (I'd expect this to prevent getting new assertions sent to any SPs.)
> 
> It does not, that's authentication only.

Would it be possible to have the authn subsystem(s) check back with
the account lockout status in a future release before succeeding?
Or would that mess up thr design somehow?
(And of course I have no idea how big of a change that would be.)

-peter


More information about the users mailing list