<div dir="ltr">after SP's "<span style="color:rgb(80,0,80);font-family:arial,sans-serif;font-size:13px">Shibboleth.sso/Logout", does the user have to close the browser to enforce a logout?</span></div><div class="gmail_extra">
<br><br><div class="gmail_quote">On Thu, Apr 25, 2013 at 9:04 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
On 4/25/13 9:52 AM, "Sam Jacob" <<a href="mailto:skjacob@gmail.com">skjacob@gmail.com</a>> wrote:<br>
<br>
>we implemented the Shibboleth.sso/Logoutbut have a question:<br>
<div class="im">>1. user logs out of SP application and calls Shibboleth.sso/Logout<br>
>2. then user logs out of the single-sign on ,ie. iDP logout<br>
>3. close the browser<br>
> Can the user still access the SP application if logged out of iDP?<br>
<br>
</div>Not if the steps you list are followed, but there are no details behind<br>
those steps. There is no standard for "logout of IdP" so unless you're<br>
doing a SAML logout or something, I don't know what you specifically refer<br>
to.<br>
<div class="im"><br>
> if the user can still access the SP application without logging into iDP<br>
>(after iDP logout) ,<br>
> what will be the reason for that ?<br>
<br>
</div>There's no way for me to answer that. You have logs, and a client you can<br>
trace the requests from, so I'd suggest you start there.<br>
<div class="im"><br>
>does SP has any control on the iDP session , or is it iDP's<br>
>responsibility to expire or remove<br>
> the cookie on iDP logout?<br>
<br>
</div>The SP has no control over the IdP's session, nor could it. It can send<br>
SAML logout requests, or issue proprietary redirects.<br>
<br>
Running the logout handler is not one thing. It's a trigger for a set of<br>
behaviors you configure in the SP, so what happens is up to you and the<br>
capabilities of the IdP.<br>
<br>
And after all that, you may have an application session to deal with.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br>Sam Jacob
</div>