<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div>
<div>
<div></div>
<div>That is part of the story.&nbsp; The so itself has control over when an auth&nbsp; is required.&nbsp; There you can combine affects of multiple attributes for different use cases.&nbsp;
</div>
<div><font style="color:#333333"><i>Sent from my Verizon Wireless 4G LTE DROID</i></font></div>
</div>
<div class="x_quote">On Dec 8, 2014 11:41 AM, Sathish Anickode &lt;SAnickode@skytouchtechnology.com&gt; wrote:<br type="attribution">
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">I would like to better understand how the user session timeout work. It appears that there is one user session on the IdP that tracks all the services where the user has authenticated and this session will timeout due to inactivity.
<br>
<br>
If my above assumptions are correct, then each time the user authenticates with a SP, the timeout on this session is reset. Can you please confirm if my understanding is correct?<br>
<br>
-----Original Message-----<br>
From: users-bounces@shibboleth.net [<a href="mailto:users-bounces@shibboleth.net">mailto:users-bounces@shibboleth.net</a>] On Behalf Of Cantor, Scott<br>
Sent: Monday, December 08, 2014 8:37 AM<br>
To: Shib Users<br>
Subject: Re: Shibboleth session vs Application session<br>
<br>
On 12/8/14, 3:25 PM, &quot;Sathish Anickode&quot; &lt;SAnickode@skytouchtechnology.com&gt;<br>
wrote:<br>
<br>
&gt;The following link<br>
&gt;(<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthnSession">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthnSession</a>)<br>
&gt;states that the user will be forced to authenticate when the user <br>
&gt;session expires even though the authentication method lifetime has not exceeded.<br>
<br>
That's true.<br>
<br>
&gt;If this is the case, can we set the user session expiration to 15 <br>
&gt;minutes and periodically refresh the session if the user is actively using an SP?<br>
<br>
The session &quot;lifetime&quot; is actually a timeout, so there is no fixed expiration. The authentication methods are explicitly a fixed duration.
<br>
And no, there is no way to do that unless you're going to do some kind of hacky polling trick.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
-- <br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>