<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
        {mso-style-priority:99;
        mso-style-link:"Plain Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
span.PlainTextChar
        {mso-style-name:"Plain Text Char";
        mso-style-priority:99;
        mso-style-link:"Plain Text";
        font-family:"Calibri","sans-serif";}
p.Default, li.Default, div.Default
        {mso-style-name:Default;
        margin:0in;
        margin-bottom:.0001pt;
        text-autospace:none;
        font-size:12.0pt;
        font-family:"Arial","sans-serif";
        color:black;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">Thanks for your reply. I wanted to additionally clarify the following:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">We are planning to use WebLogic SAML integration. Additionally, since our existing application uses container sessions extensively, we will be using our application session instead of the Shibboleth session.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Following is the PCI DSS 3.0 requirement (https://www.pcisecuritystandards.org/documents/PCI_DSS_v3.pdf ) related to session inactivity:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<table class="MsoNormalTable" border="1" cellspacing="0" cellpadding="0" style="border-collapse:collapse;border:none">
<tbody>
<tr style="height:4.7pt">
<td width="484" valign="top" style="width:290.45pt;border:none;padding:0in 5.4pt 0in 5.4pt;height:4.7pt">
<p class="MsoNormal" style="text-autospace:none"><b><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:black">PCI DSS Requirements
</span></b><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:black"><o:p></o:p></span></p>
</td>
<td width="601" valign="top" style="width:360.3pt;border:none;padding:0in 5.4pt 0in 5.4pt;height:4.7pt">
<p class="MsoNormal" style="text-autospace:none"><b><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:black">Testing Procedures
</span></b><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:black"><o:p></o:p></span></p>
</td>
<td width="778" valign="top" style="width:467.05pt;border:none;padding:0in 5.4pt 0in 5.4pt;height:4.7pt">
<p class="MsoNormal" style="text-autospace:none"><b><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:black">Guidance
</span></b><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:black"><o:p></o:p></span></p>
</td>
</tr>
<tr style="height:46.15pt">
<td width="484" valign="top" style="width:290.45pt;border:none;padding:0in 5.4pt 0in 5.4pt;height:46.15pt">
<p class="MsoNormal" style="text-autospace:none"><b><span style="font-size:9.0pt;font-family:"Arial","sans-serif";color:black">8.1.8
</span></b><span style="font-size:9.0pt;font-family:"Arial","sans-serif";color:black">If a session has been idle for more than 15 minutes, require the user to re-authenticate to re-activate the terminal or session.
<o:p></o:p></span></p>
</td>
<td width="601" valign="top" style="width:360.3pt;border:none;padding:0in 5.4pt 0in 5.4pt;height:46.15pt">
<p class="MsoNormal" style="text-autospace:none"><b><span style="font-size:9.0pt;font-family:"Arial","sans-serif";color:black">8.1.8
</span></b><span style="font-size:9.0pt;font-family:"Arial","sans-serif";color:black">For a sample of system components, inspect system configuration settings to verify that system/session idle time out features have been set to 15 minutes or less.
<o:p></o:p></span></p>
</td>
<td width="778" valign="top" style="width:467.05pt;border:none;padding:0in 5.4pt 0in 5.4pt;height:46.15pt">
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:9.0pt;font-family:"Arial","sans-serif";color:black">When users walk away from an open machine with access to critical system components or cardholder data, that machine may be used by others
in the user’s absence, resulting in unauthorized account access and/or misuse. <o:p>
</o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:9.0pt;font-family:"Arial","sans-serif";color:black">The re-authentication can be applied either at the system level to protect all sessions running on that machine, or at the application
level. <o:p></o:p></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoPlainText">Thanks.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">-----Original Message-----<br>
From: users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net] On Behalf Of Cantor, Scott<br>
Sent: Thursday, December 04, 2014 1:38 PM<br>
To: Shib Users<br>
Subject: Re: Shibboleth session vs Application session</p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">On 12/4/14, 8:27 PM, "Sathish Anickode" <<a href="mailto:SAnickode@skytouchtechnology.com"><span style="color:windowtext;text-decoration:none">SAnickode@skytouchtechnology.com</span></a>>
<o:p></o:p></p>
<p class="MsoPlainText">wrote:<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">>I find that the shibboleth session and application session are distinct
<o:p></o:p></p>
<p class="MsoPlainText">>and each have their own time to live.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">Assuming there is an application session, yes.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">> However, I wanted to confirm if the life time for session tokens behave
<o:p></o:p></p>
<p class="MsoPlainText">>as follows:<o:p></o:p></p>
<p class="MsoPlainText">><o:p> </o:p></p>
<p class="MsoPlainText">>Shibboleth session will live for a set duration while the application
<o:p></o:p></p>
<p class="MsoPlainText">>session, which also has a set duration, extends each time the application
<o:p></o:p></p>
<p class="MsoPlainText">>is accessed.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">There's no single answer to that, application sessions depend on the
<o:p></o:p></p>
<p class="MsoPlainText">application, obviously. The SP session has both a lifetime maximum and a
<o:p></o:p></p>
<p class="MsoPlainText">timeout.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">> However, Shibboleth sessions is not updated after each application
<o:p></o:p></p>
<p class="MsoPlainText">>access and does<o:p></o:p></p>
<p class="MsoPlainText">> not extend beyond the preset expiration time.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">I don't know what that means, but the SP lifetime is an absolute maximum
<o:p></o:p></p>
<p class="MsoPlainText">set up front and it never goes past that. The inactivity timeout is based
<o:p></o:p></p>
<p class="MsoPlainText">on last access and that's updated every time the session is used. I have
<o:p></o:p></p>
<p class="MsoPlainText">no idea what any application does or doesn't do, that's not in scope of my
<o:p></o:p></p>
<p class="MsoPlainText">software.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">> <o:p></o:p></p>
<p class="MsoPlainText">>As per PCI-DSS 3.0 standards, each application should have session
<o:p></o:p></p>
<p class="MsoPlainText">>timeout set to 15 minutes after which the user should be forced to
<o:p></o:p></p>
<p class="MsoPlainText">>authenticate again. Can you please let me know what would be the best
<o:p></o:p></p>
<p class="MsoPlainText">>practice for setting appropriate shibboleth session timeout to accomplish
<o:p></o:p></p>
<p class="MsoPlainText">>this requirement?<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">You'd have to start by determining what somebody saying "timeout" actually
<o:p></o:p></p>
<p class="MsoPlainText">means, because that's just not technically precise.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">-- Scott<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">-- <o:p></o:p></p>
<p class="MsoPlainText">To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
<span style="color:windowtext;text-decoration:none">users-unsubscribe@shibboleth.net</span></a><o:p></o:p></p>
</div>
</body>
</html>