<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:11pt; color:black">
<span style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:11pt; color:black">You aren't wrong. I wonder if MFA helps this situation?<br>
<br>
Sent from my Android phone using TouchDown (www.nitrodesk.com)<br>
<br>
<span style="color:black">-----Original Message----- <br>
<b>From:</b> David Bantz [dabantz@alaska.edu]<br>
<b>Received:</b> Tuesday, 15 Oct 2013, 2:59pm<br>
<b>To:</b> Shib Users [users@shibboleth.net]<br>
<b>Subject:</b> Re: IDP Logout, text asking user whether or not to kill the IDP session<br>
<br>
</span></span></div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">On Tue, 15 Oct 2013, at 13:46 , Peter Schober &lt;peter.schober@univie.ac.at&gt; wrote:<br>
&gt; <br>
&gt; <br>
&gt;&nbsp; If you want to exit your weblogin (N.B.: name of the service)<br>
&gt;&nbsp; session please click/choose<br>
&gt; <br>
&gt;&nbsp;&nbsp; [[Logout]]<br>
&gt; <br>
&gt;&nbsp; &lt;bold&gt;and completely exit your web browser&lt;/bold&gt;, e.g. via File -&gt;<br>
&gt;&nbsp; Quit.<br>
&gt; <br>
&gt;&nbsp; Alternatively you can still continue your weblogin session by<br>
&gt;&nbsp; accessing services directly.<br>
&gt; <br>
&gt; -peter<br>
<br>
Well yes, but even though you kill the IdP / SSO session cookie, <br>
if the user was logged in to other relying services, then<br>
the browser will have cookies indicating a valid session with that service.<br>
Even adding the step of exiting the browser may still enable a <br>
subsequent continuation of those other relying services once the <br>
browser is re-launched and helpfully restores that service session cookie.<br>
<br>
AFAIK, if the user doesn't &quot;log out&quot; of all the services first, then then kill <br>
the SSO session, there may be persistent session cookies.&nbsp; Alas,<br>
even if we could motivate users to log out of all services then kill the<br>
SSO session, I find services that do not implement any logout: there's <br>
no way for my IdP or web site to kill the service session cookie.<br>
<br>
I'd love to be wrong!<br>
<br>
<br>
David Bantz<br>
</div>
</span></font>
</body>
</html>