<span style="font-family: Arial;">Well I guess... <br><br>Kinda depends on which you have set longer. I tend to think of the LoginHandler time as a hard stop at that particular LH since the idea is that you could be running multiple.<br><br>sent from mobile<br><br>----- Reply message -----<br>From: &quot;Wessel, Keith&quot; &lt;kwessel@illinois.edu&gt;<br>To: &quot;Shib Users&quot; &lt;users@shibboleth.net&gt;<br>Subject: IDP session timeout<br>Date: Tue, Aug 20, 2013 5:11 PM<br><br></span><br>So, to confirm, Kevin, the session lifetime is an inactivity timer, but the login handler timeout doesn&#39;t get reset and is a max session lifetime. That correct?<br><br>Keith<br><br><br>-----Original Message-----<br>From: users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net] On Behalf Of Kevin P. Foote<br>Sent: Tuesday, August 20, 2013 3:56 PM<br>To: Shib Users<br>Subject: RE: IDP session timeout<br><br><br>On Tue, 20 Aug 2013, Wessel, Keith wrote:<br><br>&gt; Yes, I read that page before I posted. But it appears that, at least for the session value, it gets reset after a user visits the IDP from any SP. It&#39;s unclear for the login handler timeouts from that page, but I&#39;d expect it&#39;s the same: the counter gets reset after each login for that given login handler. Thus my statement about keeping my session alive on the IDP by hitting it every 29 minutes (assuming all SPs use the same login handler, that is).<br><br>The LoginHandler time is a hard stop I believe is the way Chad said it before..<br><br>------<br>thanks<br> &nbsp;kevin.foote<br>--<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>--<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>