<div dir="ltr">I'm reading up on the SLO capabillitites of Shiboleth. On <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/SLOIssues" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/SLOIssues</a> it says<div>
"<span style="color:rgb(51,51,51);font-family:Arial,Helvetica,FreeSans,sans-serif;font-size:13px;line-height:17.33333396911621px">The easiest is to remove all application level session management and rely solely on the Shibboleth SP's session management" </span></div>
<div><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="line-height:17.33333396911621px"><br></span></font></div><div><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="line-height:17.33333396911621px">Is it correct to assume that this sessionmanagement only refers to authenticated session managament. The application should not use the appliation session to validate that a user is authenticated.</span></font></div>
<div><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="line-height:17.33333396911621px"><br></span></font></div><div><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="line-height:17.33333396911621px">But its ok to store other information on the application session, right?</span></font></div>
<div><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="line-height:17.33333396911621px"><br></span></font></div><div><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif" style="font-size:13px"><span style="line-height:17.33333396911621px">If we do this and use backchannel SLO, would it be correct to assume that the SLO will work good?<br clear="all">
</span></font><div style="font-family:arial,sans-serif;font-size:13px"></div></div><div><div><br></div><div>--</div>Stefan</div>
</div>