<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"> # IDP session must be at _least_ as long as authn result lifetime<br>
<br>
doesn't seem to line up with that interpretation. Why would a session inactivity setting need to necessarily be as long as the maximum lifetime of an authn result?</blockquote><div><br></div><div>Good question. I believe that's a typo. I think it should be:</div><div><br></div><div># IDP session must be at _least_ as long as authn result timeout<br></div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"> Doesn't it just need to be as long as the longest authn result inactivity timeout that one wants to support?<br></blockquote><div><br></div><div>I think you're right. I wrote those docs to document a very important security policy area, but Scott's the authority on the design. I'll let him comment before I update the docs.</div><div><br></div><div>M</div><div><br></div></div></div>