<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:11pt; color:black">
<span style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:11pt; color:black">Closing the browser doesn't work for our cas. IE, Firefox, or chrome. And our shib is backed by cas. Sigh.<br>
<br>
Bryan<br>
<br>
Sent from my Android phone using TouchDown (www.nitrodesk.com)<br>
<br>
<span style="color:black">-----Original Message----- <br>
<b>From:</b> Jim Fox [fox@washington.edu]<br>
<b>Received:</b> Tuesday, 15 Oct 2013, 3:29pm<br>
<b>To:</b> Shib Users [users@shibboleth.net]<br>
<b>Subject:</b> Re: IDP Logout, text asking user whether or not to kill the IDP session<br>
<br>
</span></span></div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText"><br>
<br>
Steven asked what we tell people, not whether or not what we tell <br>
them actually works.<br>
<br>
In most cases I think closing the browser does kill off the session cookies.<br>
Are there browsers where a user cannot even configure it to work corectly?<br>
<br>
<br>
Jim<br>
<br>
> <br>
> Well, at least logout does not work at all. Exiting browsers doesn't work.<br>
><br>
> -Bryan<br>
><br>
><br>
><br>
> On 10/15/13 3:31 PM, "Jim Fox" <fox@washington.edu> wrote:<br>
><br>
>><br>
>> It was always RL Bob's insistence that logging out of an app should not<br>
>> necesssarily log one out of SSO. When someone logs out of an app,<br>
>> be it a shib sp or a weblogin sp, the user gets redirected to the weblogin<br>
>> service where she is told, "You have logged out of xxxxxx. You are still<br>
>> logged in to weblogin as yyy. Completely exit your browser to log out<br>
>> of weblogin."<br>
>><br>
>> Something like that.<br>
>><br>
>> Jim<br>
>><br>
>><br>
>> On Tue, 15 Oct 2013, Steven Carmody wrote:<br>
>><br>
>>> Date: Tue, 15 Oct 2013 14:20:20 -0700<br>
>>> From: Steven Carmody <steven_carmody@brown.edu><br>
>>> To: users@shibboleth.net<br>
>>> Reply-To: Shib Users <users@shibboleth.net><br>
>>> Subject: IDP Logout, text asking user whether or not to kill the IDP<br>
>>> session<br>
>>><br>
>>> Hi,<br>
>>><br>
>>> We're being presented with situations where it makes sense to have the<br>
>>> user click a Logout button on the App, and be returned to the IDP Logout<br>
>>> endpoint.<br>
>>><br>
>>> IDP 2.4 includes support for that endpoint (and just destroys the<br>
>>> session cookie). However, in our case, if the user is returned to that<br>
>>> IDP endpoint we'd prefer to display a page asking the user if they want<br>
>>> the IDP session destroyed; if they click YES then proceed. In most cases<br>
>>> we expect they won't want to kill the IDP session.<br>
>>><br>
>>> The problem is "how to ask that question". Most of the terms that<br>
>>> denizens of this list use as part of that question aren't suitable for<br>
>>> use when asking that question of a non-computer person.<br>
>>><br>
>>> I'm wondering if other sites that have faced this situation are willing<br>
>>> to share the text they've used to present this question ?<br>
>>><br>
>>> Thanks in advance!<br>
>>> --<br>
>>> To unsubscribe from this list send an email to<br>
>>> users-unsubscribe@shibboleth.net<br>
>>><br>
>> --<br>
>> To unsubscribe from this list send an email to<br>
>> users-unsubscribe@shibboleth.net<br>
><br>
> --<br>
> To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
><br>
--<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>