<div dir="ltr">hi all,<br>i have my shibboleth idp and my sp side configured and now i wanted to setup the idp session settings and have gone through the official documentation but wanted some more help on a few points.<br>idp.session.timeout is by default 60m..what security and resource issues are most likely to happen when i increase the timeout to say 24h.<br>idp.authn.defaultlifetime=PT60M<br>idp.authn.defaultTimeout=PT30M<br><br>similarly what security and resource based problems am i most likely to encounter on increasing the defualtlifetime to say 8hrs and defaultimeout accordingly.<br><br>On a related topic, i also need clarification on the following problem,to explain which lets take the following example:<br><br>If Suppose IDP is configured such that idp.authn.defaultTimeout is 60 minutes while the idp.authn.defaultLifetime is 120 min, SP session timeout is 120 minutes. There is only activity at front channel at SP but no back end channel activity. Then after 60 minutes,IDP timeout will occur due to inactivity but SP session is still valid and then suppose SP redirects to SP2 after 90 mins from initial login time which follows the same SSO settings so it will then not get authenticated and get redirected to IDP login page. How can i manage the session configuration so as to avoid such conditions without compromising on security??<br><br>P.S. i have already referred to following links:<br><br><a href="https://wiki.shibboleth.net/confluence/display/IDP30/SessionConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/SessionConfiguration</a><br><a href="https://wiki.shibboleth.net/confluence/display/IDP30/Sessions">https://wiki.shibboleth.net/confluence/display/IDP30/Sessions<br></a><br>Thanks<br>-- <br>Priyanshu Bhalotia<br>Platform Engineer<br>Wooqer</div>