<div dir="ltr">You could enable the IdP's logout support <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableSLO">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableSLO</a>. No, it's not true SLO, but it will kill the SSO session. What our highly-sensitive apps tend to do, since they don't even trust the user to close the browser, is use a combination of short-idle timers + forceAuthn. We have not at this time decided to make any changes to our IdP (or even enable the SLO features) in response to this.<div><br></div><div>Dave</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Feb 20, 2015 at 2:40 PM, Dunn, Adam M <span dir="ltr"><<a href="mailto:Adam.M.Dunn@uth.tmc.edu" target="_blank">Adam.M.Dunn@uth.tmc.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">We've recently been seeing a large number of Chrome users turn up with an advanced setting in Chrome to leave it running in the background after closing ALL browsers. None of them seem to have any knowledge of turning this on, so it would seem that it's being done by default.<br>
<br>
This is a concern to us for SSO enabled applications that leverage local logout, where we display an instruction telling users to close all of their browser windows if they wish to complete the logout process. With this Chrome setting that practice does you no good since Chrome never really closes.<br>
<br>
I understand it's a browser issue, and the fix is to tell users to disable this, but most users will know nothing about how to muck with these settings. We're looking at pushing an enterprise GPO setting to disable this, but that doesn't begin to do anything for personal devices.<br>
<br>
Short of using SLO for every app (many of which don't support it), I'm curious to know how are others addressing this issue with Chrome?<br>
<br>
<br>
Thanks,<br>
Adam<br>
<span class="HOEnZb"><font color="#888888">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature">David Langenberg<div>Identity & Access Management</div><div>The University of Chicago</div></div>
</div>