Shared computer and SAML SSO logout
Lohr, Donald A - lohrda
lohrda at jmu.edu
Wed Mar 15 18:13:50 UTC 2023
Are my assumptions correct that this is not a Shibboleth IdP issue but a
SAML issue?
Thanks,
Don
On 3/15/23 11:47 AM, Cantor, Scott wrote:
> CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.
> ________________________________
>
> Since logout is and will probably always be hopeless, there are two options, one realistic and one only semi-practical.
>
> The primary tool is the option on the password login form to signify it's a shared machine. That requires user choice but it's the only practical way. That prevents SSO via a client signal.
>
> The other option is controlling the network from which the machines connect and scripting the system to prevent login reuse for them based on the client address. That is limited in scope and ultimately has never gone very far for me.
>
> I don't know of any other practical means of identifying shared machines that could be trusted.
>
> -- Scott
>
>
--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230315/42a4df1d/attachment.htm>
More information about the users
mailing list