force termination of SSO session?
Les LaCroix
llacroix at carleton.edu
Fri Jul 23 13:39:27 UTC 2021
>
> I think the suggestion to use a directory attribute is probably more
> appropriate, and that can easily fail closed if desired.
I haven't looked at the account lockout feature except for skimming the
wiki page. If it's activated via API, does its state remain across an IdP
restart/reboot? I also assume you'd have to call the API for every member
of the cluster for it to have the desired effect in an adverse termination
situation; but you know what they say about "assume". Those aren't issues
for something based on directory attributes.
-Les
<http://www.carleton.edu/>
*Les LaCroix '79*
Strategic Technologist
Information Technology Services
t: (507) 222-5455
On Fri, Jul 23, 2021 at 7:45 AM Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 7/23/21, 3:16 AM, "users on behalf of Peter Schober" <
> users-bounces at shibboleth.net on behalf of peter.schober at univie.ac.at>
> wrote:
>
> > Would it be possible to have the authn subsystem(s) check back with
> > the account lockout status in a future release before succeeding?
>
> Lockout is based on the username (and usually a client address) that gets
> passed into authentication and in the stage you're talking about that's
> long gone and is quite likely something completely different in many
> deployments after normalization. Plus since it's generally address
> specific, it's easy to circumvent in exactly the situations an
> administrative logout would be trying to address.
>
> I think the suggestion to use a directory attribute is probably more
> appropriate, and that can easily fail closed if desired.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210723/4d8f02ea/attachment.htm>
More information about the users
mailing list