Administrative logout

Cantor, Scott cantor.2 at osu.edu
Thu Jan 25 22:42:58 UTC 2024


> Is it possible to provide a working example of how one could configure
> attribute based revocation for administrative logout? 

Not sure what you're looking for, it's literally just "an attribute that contains the timestamp before which to revoke". The documentation is explicit about the requirements for the attribute's value.

Some have suggested doing it with a "password changed" attribute so that any time a password changes, it revokes existing sessions, which avoids the need for a new attribute or process.

-- Scott




More information about the users mailing list