<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Arial,Helvetica,sans-serif;" dir="ltr">
<p>Aaron,</p>
<p><br>
</p>
<p>IANAD, but I think I can interpret both of those.</p>
<p><br>
</p>
<p>Slop would be keeping the IdP's own sessions around slightly longer to prevent unnecessary errors in the event a logout request is received.  A lot of places like to use nearly synchronous session lifetimes for applications and logins.</p>
<p><br>
</p>
<p>Default SP lifetime is harder to guess to full scope of because SAML doesn't really constrain how long the session at the SP should live for.  Instead, that's likely to be how long to keep an SP associated with a session at the IdP -- timing out that particular
 interaction rather than the user's SSO session, to which it is affixed.  The lifetime of the assertion itself is nominal.</p>
<p><br>
</p>
<p>I'm an advocate for exposing IdP sessions for query stringable operations by SP's protected with client TLS, in which setting this would all be more tightly laced and hopefully intuitive, but I'm not aware of widescale federated use of that in the wild.</p>
<p><br>
</p>
<p>We'll find out if I'm wrong,</p>
<p>Nate.</p>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Aaron Howell <aaron.howell@deakin.edu.au><br>
<b>Sent:</b> Wednesday, April 26, 2017 5:07:23 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> idp.session.slop</font>
<div> </div>
</div>
<div>
<div class="">"idp.session.slop - Extra time after expiration before removing IdP sessions in case a logout is invoked” - <a href="https://wiki.shibboleth.net/confluence/display/IDP30/AuthenticationConfiguration" class="">https://wiki.shibboleth.net/confluence/display/IDP30/AuthenticationConfiguration</a></div>
<div class=""><br class="">
</div>
<div class="">Is "IdP sessions" correct - or is it meant to be "SP sessions” ?</div>
<div class=""><br class="">
</div>
<div class="">And what is the difference between using this setting and idp.session.defaultSPlifetime?</div>
<div class=""><br class="">
</div>
<div class="">Cheers,</div>
<div class="">Aaron</div>
<span style="font-size: 9.0pt; font-family: 'Calibri'; "><em><strong><br>
Important Notice:</strong> The contents of this email are intended solely for the named addressee and are confidential; any unauthorised use, reproduction or storage of the contents is expressly prohibited. If you have received this email in error, please delete
 it and any attachments immediately and advise the sender by return email or telephone.<br>
<br>
Deakin University does not warrant that this email and any attachments are error or virus free.</em></span>
</div>
</body>
</html>