<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    -----BEGIN PGP SIGNED MESSAGE-----<br>
    Hash: SHA1<br>
    <br>
    On 9/29/11 5:23 PM, Cantor, Scott wrote:<br>
    <span style="white-space: pre;">&gt; <br>
      &gt; No, mostly because logout of a local app is not terribly
      useful,</span><br>
    <br>
    &nbsp;&nbsp;&nbsp; I understand what you are saying from a Web SSO perspective, but
    in our particular use case, it happens to be useful.<br>
    <br>
    <span style="white-space: pre;">&gt; and <br>
      &gt; because your situation is pretty unusual. Almost all apps
      have a<br>
      &gt; logout hook of some kind if they do anything at all.</span><br>
    <br>
    &nbsp;&nbsp; This app does have a logout hook, and it was very useful for
    calling the session logout code for SimpleSAMLPHP. I'd like to
    convert the app to the native SP and use the same hook, however a
    browser redirect introduces a lot more side effects than was
    originally planned for this logout hook. I can still use the hook, I
    just wanted to explore other options - such as expiring the SP
    session before even calling the CMS logout code.<br>
    <br>
    &nbsp;&nbsp;&nbsp; Steve<br>
    -----BEGIN PGP SIGNATURE-----<br>
    Version: GnuPG/MacGPG2 v2.0.12 (Darwin)<br>
    Comment: Using GnuPG with Mozilla - <a class="moz-txt-link-freetext" href="http://enigmail.mozdev.org/">http://enigmail.mozdev.org/</a><br>
    <br>
    iEYEARECAAYFAk6FQ9wACgkQcVd2YI1BWAip+gCfUS5mniDApJlHGIazogcFzCEO<br>
    w9EAn2FOWJMr4LlXVh/zeEv4eswA8jq/<br>
    =Je0s<br>
    -----END PGP SIGNATURE-----<br>
    <br>
  </body>
</html>