<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.hoenzb
        {mso-style-name:hoenzb;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Dave, thanks.&nbsp; That’s a good point about forced re-authentication.&nbsp; While it erodes the idea behind SSO, I think it could help mitigate this problem for the
 time being on some important apps.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>David Langenberg<br>
<b>Sent:</b> Friday, February 20, 2015 3:52 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: Chrome background process affecting logouts<o:p></o:p></span></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class="MsoNormal">You could enable the IdP's logout support&nbsp;<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_SHIB2_IdPEnableSLO&amp;d=AwMFaQ&amp;c=6vgNTiRn9_pqCD9hKx9JgXN1VapJQ8JVoF8oWH1AgfQ&amp;r=Ri6WeaSB__co_pfxpFYxuHcYBY05bStjH_HuZWtd23Y&amp;m=KiRzARf6VwIfOvU2xb5ym8Zml3fkqIOEOZWcLfkjEFM&amp;s=quClsGMZWB3_s1WeD_lqk7dKg2WdiNO7uXH2SMIA4lU&amp;e=">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableSLO</a>.&nbsp;
 No, it's not true SLO, but it will kill the SSO session.&nbsp; What our highly-sensitive apps tend to do, since they don't even trust the user to close the browser, is use a combination of short-idle timers &#43; forceAuthn.&nbsp; We have not at this time decided to make
 any changes to our IdP (or even enable the SLO features) in response to this.<o:p></o:p></p>
<div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class="MsoNormal">Dave<o:p></o:p></p>
</div>
</div>
<div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class="MsoNormal">On Fri, Feb 20, 2015 at 2:40 PM, Dunn, Adam M &lt;<a href="mailto:Adam.M.Dunn@uth.tmc.edu" target="_blank">Adam.M.Dunn@uth.tmc.edu</a>&gt; wrote:<o:p></o:p></p>
<p class="MsoNormal">We've recently been seeing a large number of Chrome users turn up with an advanced setting in Chrome to leave it running in the background after closing ALL browsers.&nbsp; None of them seem to have any knowledge of turning this on, so it would
 seem that it's being done by default.<br>
<br>
This is a concern to us for SSO enabled applications that leverage local logout, where we display an instruction telling users to close all of their browser windows if they wish to complete the logout process.&nbsp; With this Chrome setting that practice does you
 no good since Chrome never really closes.<br>
<br>
I understand it's a browser issue, and the fix is to tell users to disable this, but most users will know nothing about how to muck with these settings.&nbsp; We're looking at pushing an enterprise GPO setting to disable this, but that doesn't begin to do anything
 for personal devices.<br>
<br>
Short of using SLO for every app (many of which don't support it), I'm curious to know how are others addressing this issue with Chrome?<br>
<br>
<br>
Thanks,<br>
Adam<br>
<span class="hoenzb"><span style="color:#888888">--</span></span><span style="color:#888888"><br>
<span class="hoenzb">To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></span></span><o:p></o:p></p>
</div>
<p class="MsoNormal"><br>
<br clear="all">
<o:p></o:p></p>
<div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class="MsoNormal">-- <o:p></o:p></p>
<div>
<p class="MsoNormal">David Langenberg<o:p></o:p></p>
<div>
<p class="MsoNormal">Identity &amp; Access Management<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">The University of Chicago<o:p></o:p></p>
</div>
</div>
</div>
</div>
</body>
</html>