<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
Ajay,
<div><br>
</div>
<div>
<div>
<blockquote type="cite">
<div style="font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: transparent; ">
<span style="background-color: transparent; ">Does it look like a typically Un-solicitated SSO flow or am I missing something? Is there any other clean-up/graceful resource release that should be done?</span></div>
</blockquote>
<div><br>
</div>
<div>This is reasonably standard for an unsolicited SSO flow, and somewhat more graceful given the partial logout so long as you display appropriate messaging to users once that's completed.</div>
<br>
<blockquote type="cite">
<div style="font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: transparent; ">
What factors I should consider to arrive at various session timeouts? On an average, users stay at the SP site for about 10 minutes.&nbsp;</div>
<div style="font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: transparent; ">
<br>
</div>
<div style="font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: transparent; ">
<span style="font-size: 10pt; ">To begin with, I have configured both my web application (web.xml session-timeout) and Shibboleth IDP (</span><span style="font-size: 10pt; ">shibboleth.SessionManager constructor argument in internal.xml and LoginHandler authenticationDuration
 in handler.xml</span><span style="font-size: 10pt; background-color: transparent; ">) session time out &nbsp;to 20 minutes. I have a feeling that these two should usually match. &nbsp;</span></div>
</blockquote>
<div><br>
</div>
<div>They should.</div>
<br>
<blockquote type="cite">
<div style="font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: transparent; ">
<span style="background-color: transparent; font-size: 10pt; ">Should I ask SP to configure their session-timeout to also 20 minutes?&nbsp;</span></div>
<div style="font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: transparent; ">
<br>
</div>
<div style="font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: transparent; ">
Are their any guidelines for arriving at session timeout in such Un-solicitated SSO cases? Should all the three match? Or, do the two timeouts at my end be larger than the Vendor SP timeout? &nbsp;</div>
</blockquote>
</div>
<br>
</div>
<div>It's very hard to give any coherent advice on timeouts. &nbsp;It totally depends on your use case. &nbsp;I don't know if this IdP is also used for other applications, and if not, what your desired behavior here is. &nbsp;You may be able to get away with purging the user's
 session at the IdP after a very short duration of time if you don't expect any single-sign-on behavior with any other SP.</div>
<div><br>
</div>
<div>Very short session expiration on the order of 20 minutes may be applicable for applications that protect sensitive data using lightweight authentication anyway.</div>
<div><br>
</div>
<div>Sorry to not be able to give better guidance here, but &quot;it depends&quot;.</div>
<div>Nate.</div>
</body>
</html>