<html>
<head>
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<p>Hi list,</p>
<p>I need to revoke my findings. I have tested this again: same
user, same SP, using a non-tranisent NameID (uid). <br>
</p>
<p>The flow: Login in Browser A, Login in Browser B, _wait an hour_,
Logout in Browser B, then Logout in Browser A. <br>
</p>
<p>This is what happens when using SAML SLO
(<SP>/Shibboleth.sso/Logout): upon the second logout, the
IdP returns the SessionNotFound Error, no propagation, the Browser
A user is still logged in at the SP.</p>
<p>This is what happens when using the proprietary SLO
(<IdP>/idp/profile/Logout): upon the second logout, the IdP
says the logout is completed, however no propagation and the
Browser A user is still logged in at the SP.</p>
<p>I can provide debug logs to highlight the difference between
correct and incorrect SAML SSO on the one hand, and correct and
incorrect proprietary Logout.<br>
</p>
<p>What ways would you recommend to handle this? In our set-up, the
flow sketched will happen frequently. However I could tweak almost
every variable in the IdP and SP since I basically control them.
The shared accounts are marked in our LDAP, so the last resort
would be to write an IdP intercepter that tells these users to be
careful about SLO. Other ideas? <br>
</p>
<p>Regards</p>
<p>Martin<br>
</p>
P.S. what puzzles me is that without waiting the hour, everything
seemed to work. Is there some setting besides the ones in
idp.properties that dictates this hour lag? Something in conf/authn?<br>
<br>
<br>
<div class="moz-cite-prefix">On 21.04.2017 10:09, Martin Haase
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:2205916a-c51a-1d13-8122-02e3d222c34c@DAASI.de">
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
<p>...and yet another finding: issuing an invariable (i.e.
non-transient) NameID at the IdP (e.g. persistent, email, or
unspecified) does *not* cause the SessionNotFound error, so this
is another possible solution.</p>
<p>Cheers</p>
<p>Martin<br>
</p>
<br>
<div class="moz-cite-prefix">On 21.04.2017 09:23, Martin Haase
wrote:<br>
</div>
<blockquote
cite="mid:b5877558-d6b7-4c01-2c3e-fac0b0890210@DAASI.de"
type="cite">
<pre wrap="">Hi again Scott,
thinking about it a second time, mitigating the error message about this
would be helpful, because sharing accounts is what people do. Because
this is actually common in our project, I think we will switch to the
"Simple Logout", which seems work regardless.
Thanks again,
Martin
On 20.04.2017 19:19, Cantor, Scott wrote:
</pre>
<blockquote type="cite">
<pre wrap="">But just glancing at the code, I could imagine some less ambitious changes that might address your specific issue because that's more about the reverse mapping step.
</pre>
</blockquote>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
Dr. Martin Haase, Solutions Engineer
DAASI International GmbH
Europaplatz 3
D-72072 Tübingen
Germany
phone: +49 7071 407109-0
fax: +49 7071 407109-9
email: <a class="moz-txt-link-abbreviated" href="mailto:martin.haase@daasi.de" moz-do-not-send="true">martin.haase@daasi.de</a>
web: <a class="moz-txt-link-abbreviated" href="http://www.daasi.de" moz-do-not-send="true">www.daasi.de</a>
Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz
</pre>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
Dr. Martin Haase, Solutions Engineer
DAASI International GmbH
Europaplatz 3
D-72072 Tübingen
Germany
phone: +49 7071 407109-0
fax: +49 7071 407109-9
email: <a class="moz-txt-link-abbreviated" href="mailto:martin.haase@daasi.de">martin.haase@daasi.de</a>
web: <a class="moz-txt-link-abbreviated" href="http://www.daasi.de">www.daasi.de</a>
Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz
</pre>
</body>
</html>