<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">Granted that there is no really great solution to respond to the varied and sometimes contradictory requirements of services and users, I'd nevertheless beg for your suggested improvements to the following local practice:<div><br></div><div>(1) We do have a link in our IdP which services could (re-)direct a browser that destroys the IdP SSO session cookie.</div><div><br></div><div>(2) That link can optionally re-direct again to any landing page (that is, back at the service, or to a generic 'SSO session ended' page, or…).</div><div><br></div><div>For SPs that ask us to provide a "logout URL" the user experience is:</div><div><br></div><div>1. "Logout" in the SP</div><div>2. re-direct to a page that states:</div><blockquote style="margin: 0 0 0 40px; border: none; padding: 0px;"><div><blockquote type="cite"><h3 id="YouhavebeenloggedoutofFaculty180." style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 14px; margin-left: -18px; background-color: rgb(255, 255, 255); position: static; z-index: auto; ">You have been logged out of Faculty180.</h3></blockquote></div><div><blockquote type="cite"><p style="font-family: Verdana, Arial, 'Bitstream Vera Sans', Helvetica, sans-serif; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); ">You can log in again at the&nbsp;<a class="ext-link" href="http://www.data180.com/faculty180/uaf_dev" style="text-decoration: none; color: rgb(187, 0, 0); border-bottom-width: 1px; border-bottom-style: dotted; border-bottom-color: rgb(187, 187, 187); "><span class="icon" style="background-image: url(https://iam.alaska.edu/trac/chrome/common/extlink.gif); padding-left: 12px; background-position: 50% 50%; background-repeat: no-repeat no-repeat; ">&nbsp;</span>Faculty180 web site</a>&nbsp;for UAF.</p></blockquote></div><div><blockquote type="cite"><h4 id="YourcurrentSingle-Sign-OnSSOsessionisstillactive" style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); ">Your current Single-Sign-On (SSO) session is still active</h4></blockquote></div><div><blockquote type="cite"><p style="font-family: Verdana, Arial, 'Bitstream Vera Sans', Helvetica, sans-serif; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); position: static; z-index: auto; ">An SSO session was established when you entered your credentials at UA. SSO enables you to authenticate to (log in to) Faculty180 and other sites that rely on UA's privacy-preserving SSO (those services never see your password). Examples include&nbsp;<a class="ext-link" href="http://proxy.library.uaf.edu/login" style="text-decoration: none; color: rgb(187, 0, 0); border-bottom-width: 1px; border-bottom-style: dotted; border-bottom-color: rgb(187, 187, 187); "><span class="icon" style="background-image: url(https://iam.alaska.edu/trac/chrome/common/extlink.gif); padding-left: 12px; background-position: 50% 50%; background-repeat: no-repeat no-repeat; ">&nbsp;</span>UAF library resources</a>,&nbsp;<a class="ext-link" href="https://atomic.alaska.edu/" style="text-decoration: none; color: rgb(187, 0, 0); border-bottom-width: 1px; border-bottom-style: dotted; border-bottom-color: rgb(187, 187, 187); "><span class="icon" style="background-image: url(https://iam.alaska.edu/trac/chrome/common/extlink.gif); padding-left: 12px; background-position: 50% 50%; background-repeat: no-repeat no-repeat; ">&nbsp;</span>Atomic Learning</a>,<a class="ext-link" href="https://www.educause.edu/user/wayf?entityID=https%3A%2F%2Fwww.educause.edu%2Fshibboleth-sp&amp;return=https%3A%2F%2Fwww.educause.edu%2FShibboleth.sso%2FDS%3FSAMLDS%3D1%26target%3Dcookie%253Ae926eb01&amp;&amp;dst=&amp;user_idp=urn:mace:incommon:alaska.edu" style="text-decoration: none; color: rgb(187, 0, 0); border-bottom-width: 1px; border-bottom-style: dotted; border-bottom-color: rgb(187, 187, 187); "><span class="icon" style="background-image: url(https://iam.alaska.edu/trac/chrome/common/extlink.gif); padding-left: 12px; background-position: 50% 50%; background-repeat: no-repeat no-repeat; ">&nbsp;</span>Educause</a>,&nbsp;<a class="ext-link" href="http://www.alaska.edu/uaalerts/" style="text-decoration: none; color: rgb(187, 0, 0); border-bottom-width: 1px; border-bottom-style: dotted; border-bottom-color: rgb(187, 187, 187); "><span class="icon" style="background-image: url(https://iam.alaska.edu/trac/chrome/common/extlink.gif); padding-left: 12px; background-position: 50% 50%; background-repeat: no-repeat no-repeat; ">&nbsp;</span>UA Alerts Portal</a>, and others.</p></blockquote></div><div><blockquote type="cite"><h4 id="RemovingYourSingle-Sign-Onsession" style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); ">Removing Your Single-Sign-On session</h4></blockquote></div><div><blockquote type="cite"><p style="font-family: Verdana, Arial, 'Bitstream Vera Sans', Helvetica, sans-serif; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); position: static; z-index: auto; ">You can end your SSO session by clicking on the link below; this will force authentication (require entry of credentials) for subsequent services that would otherwise rely on your existing SSO session. Removing your SSO session does NOT log you out of any services to which you are currently authenticated.&nbsp;</p></blockquote></div><div><blockquote type="cite"><p style="font-family: Verdana, Arial, 'Bitstream Vera Sans', Helvetica, sans-serif; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); position: static; z-index: auto; "><font color="#bb0000"><b>-&gt;&nbsp;</b></font><b>End My Current UA SSO Session</b></p></blockquote></div><div><blockquote type="cite"><h4 id="Risksofdatacachedinyourbrowser:" style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); ">Risks of data cached in your browser:</h4></blockquote></div><div><blockquote type="cite"><p style="font-family: Verdana, Arial, 'Bitstream Vera Sans', Helvetica, sans-serif; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); ">If the computer/tablet/phone you are using is shared with others, and you wish to limit the risk that others will be able to view or use information that may be cached in your web browser, you can reduce (but not eliminate) such risk by the following practices.</p></blockquote></div></blockquote><div><h3 id="YouhavebeenloggedoutofFaculty180." style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 14px; margin-left: -18px; background-color: rgb(255, 255, 255); position: static; z-index: auto; "></h3><blockquote type="cite"><h3 id="YouhavebeenloggedoutofFaculty180." style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 14px; margin-left: -18px; background-color: rgb(255, 255, 255); position: static; z-index: auto; "><a class="anchor" href="https://iam.alaska.edu/trac/wiki/Faculty180Logout#YouhavebeenloggedoutofFaculty180." title="Link to this section" style="text-decoration: none; color: rgb(215, 215, 215); border: none; font-size: 0.8em; vertical-align: text-top; visibility: hidden; "></a></h3><h4 id="YourcurrentSingle-Sign-OnSSOsessionisstillactive" style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); "><a class="anchor" href="https://iam.alaska.edu/trac/wiki/Faculty180Logout#YourcurrentSingle-Sign-OnSSOsessionisstillactive" title="Link to this section" style="text-decoration: none; color: rgb(215, 215, 215); border: none; font-size: 0.8em; vertical-align: text-top; visibility: hidden; "></a></h4><h4 id="RemovingYourSingle-Sign-Onsession" style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); "><a class="anchor" href="https://iam.alaska.edu/trac/wiki/Faculty180Logout#RemovingYourSingle-Sign-Onsession" title="Link to this section" style="text-decoration: none; color: rgb(215, 215, 215); border: none; font-size: 0.8em; vertical-align: text-top; visibility: hidden; "></a></h4><h4 id="Risksofdatacachedinyourbrowser:" style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); "><a class="anchor" href="https://iam.alaska.edu/trac/wiki/Faculty180Logout#Risksofdatacachedinyourbrowser:" title="Link to this section" style="text-decoration: none; color: rgb(215, 215, 215); border: none; font-size: 0.8em; vertical-align: text-top; visibility: hidden; "></a></h4><ul style="font-family: Verdana, Arial, 'Bitstream Vera Sans', Helvetica, sans-serif; font-size: 12.800000190734863px; background-color: rgb(255, 255, 255); "><ul><li><span style="font-size: 12.800000190734863px; ">Use browsers' "private browsing" option to limit sharing or storing information outside the browser window.</span></li><li><span style="font-size: 12.800000190734863px; ">Explicitly log out of all web sites; do not rely solely on closing the browser or browser window.</span></li><li><span style="font-size: 12.800000190734863px; ">Never take up the browser's suggestion to save passwords or "remember me," as that may enable others to log in as you!</span></li><li><span style="font-size: 12.800000190734863px; ">Explicitly clear the cookies and caches in your browser (brief directions for common browsers are below).</span></li><li><span style="font-size: 12.800000190734863px; ">Close (exit) the browser.</span></li></ul></ul></blockquote><br></div><div>3. &nbsp;If the user chooses the link to "End…SSO", the IdP cookie is destroyed and the browser re-directed to display:</div><div><br></div><blockquote style="margin: 0 0 0 40px; border: none; padding: 0px;"><div><blockquote type="cite"><h3 id="YourUASingle-Sign-Onsessionhasbeenterminated" style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 14px; margin-left: -18px; background-color: rgb(255, 255, 255); ">Your UA Single-Sign-On session has been terminated</h3></blockquote></div><div><blockquote type="cite"><p style="font-family: Verdana, Arial, 'Bitstream Vera Sans', Helvetica, sans-serif; font-size: 13px; background-color: rgb(255, 255, 255); ">This will force authentication (require entry of credentials) for subsequent services that would otherwise rely on your existing SSO session.&nbsp;<em>Removing your SSO session does NOT log you out of any individual services to which you are currently authenticated (logged in).</em></p></blockquote></div><div><blockquote type="cite"><h4 id="Risksofdatacachedinyourbrowser:" style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 13px; background-color: rgb(255, 255, 255); ">Risks of data cached in your browser:</h4></blockquote></div><div><blockquote type="cite"><p style="font-family: Verdana, Arial, 'Bitstream Vera Sans', Helvetica, sans-serif; font-size: 13px; background-color: rgb(255, 255, 255); ">If the computer/tablet/phone you are using is shared with others, and you wish to limit the risk that others will be able to view or use information that may be cached in your web browser, you can reduce (but not eliminate) such risk by the following practices.</p></blockquote></div></blockquote><div><h3 id="YourUASingle-Sign-Onsessionhasbeenterminated" style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 14px; margin-left: -18px; background-color: rgb(255, 255, 255); "></h3><blockquote type="cite"><h3 id="YourUASingle-Sign-Onsessionhasbeenterminated" style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 14px; margin-left: -18px; background-color: rgb(255, 255, 255); "><a class="anchor" href="https://iam.alaska.edu/trac/wiki/SSOsessionDestroyed#YourUASingle-Sign-Onsessionhasbeenterminated" title="Link to this section" style="text-decoration: none; color: rgb(215, 215, 215); border: none; font-size: 0.8em; vertical-align: text-top; visibility: hidden; "></a></h3><h4 id="Risksofdatacachedinyourbrowser:" style="font-family: Arial, Verdana, 'Bitstream Vera Sans', Helvetica, sans-serif; page-break-after: avoid; font-size: 13px; background-color: rgb(255, 255, 255); "><a class="anchor" href="https://iam.alaska.edu/trac/wiki/SSOsessionDestroyed#Risksofdatacachedinyourbrowser:" title="Link to this section" style="text-decoration: none; color: rgb(215, 215, 215); border: none; font-size: 0.8em; vertical-align: text-top; visibility: hidden; "></a></h4><ul style="font-family: Verdana, Arial, 'Bitstream Vera Sans', Helvetica, sans-serif; font-size: 13px; background-color: rgb(255, 255, 255); "><ul><li>Use browsers' "private browsing" option to limit sharing or storing information outside the browser window.</li><li>Explicitly log out of all web sites; do not rely solely on closing the browser or browser window.</li><li>Never take up the browser's suggestion to save passwords or "remember me," as that may enable others to log in as you!</li><li>Explicitly clear the cookies and caches in your browser (brief directions for common browsers are below).</li></ul></ul></blockquote><blockquote type="cite"><ul style="font-family: Verdana, Arial, 'Bitstream Vera Sans', Helvetica, sans-serif; font-size: 13px; background-color: rgb(255, 255, 255); "><ul><li>Close (exit) the browser.</li></ul></ul></blockquote><div><br></div><span class="Apple-tab-span" style="white-space:pre">                        </span><br><div><br></div></div><div><br></div><div><div><div><div>On Thu, 8 Nov 2012, at 13:35 , Jim Fox &lt;<a href="mailto:fox@washington.edu">fox@washington.edu</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><br>Correct. &nbsp;We need to add more detailed instructions.<br><br>Jim<br><br><br>On Thu, 8 Nov 2012, David Bantz wrote:<br><br><blockquote type="cite">Date: Thu, 8 Nov 2012 14:26:30 -0800<br>From: David Bantz &lt;<a href="mailto:dabantz@Alaska.edu">dabantz@Alaska.edu</a>&gt;<br>To: Shib Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>Reply-To: Shib Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>Subject: Re: logout and misc Qs --shib idp<br>But as we're seeing some browsers save cookie and browsing data, then "helpfully" auto-re-connect on the next browser launch unless the browser is<br>explicitly configured not to do so; perhaps yet another sentence is needed to so inform users.<br>David Bantz<br>UA OIT IAM<br>On Thu, 8 Nov 2012, at 12:35 , Jim Fox &lt;<a href="mailto:fox@washington.edu">fox@washington.edu</a>&gt; wrote:<br><br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;To protect your privacy and prevent unauthorized use, completely exit<br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;your Web browser when you are finished browsing. ...<br></blockquote>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div><br></div></div></body></html>