<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html;
      charset=windows-1252">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p>Hi list,</p>
    <p>I need to revoke my findings. I have tested this again: same
      user, same SP, using a non-tranisent NameID (uid). <br>
    </p>
    <p>The flow: Login in Browser A, Login in Browser B, _wait an hour_,
      Logout in Browser B, then Logout in Browser A. <br>
    </p>
    <p>This is what happens when using SAML SLO
      (<SP>/Shibboleth.sso/Logout): upon the second logout, the
      IdP returns the SessionNotFound Error, no propagation, the Browser
      A user is still logged in at the SP.</p>
    <p>This is what happens when using the proprietary SLO
      (<IdP>/idp/profile/Logout): upon the second logout, the IdP
      says the logout is completed, however no propagation and the
      Browser A user is still logged in at the SP.</p>
    <p>I can provide debug logs to highlight the difference between
      correct and incorrect SAML SSO on the one hand, and correct and
      incorrect proprietary Logout.<br>
    </p>
    <p>What ways would you recommend to handle this? In our set-up, the
      flow sketched will happen frequently. However I could tweak almost
      every variable in the IdP and SP since I basically control them.
      The shared accounts are marked in our LDAP, so the last resort
      would be to write an IdP intercepter that tells these users to be
      careful about SLO. Other ideas? <br>
    </p>
    <p>Regards</p>
    <p>Martin<br>
    </p>
    P.S. what puzzles me is that without waiting the hour, everything
    seemed to work. Is there some setting besides the ones in
    idp.properties that dictates this hour lag? Something in conf/authn?<br>
    <br>
    <br>
    <div class="moz-cite-prefix">On 21.04.2017 10:09, Martin Haase
      wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:2205916a-c51a-1d13-8122-02e3d222c34c@DAASI.de">
      <meta content="text/html; charset=windows-1252"
        http-equiv="Content-Type">
      <p>...and yet another finding: issuing an invariable (i.e.
        non-transient) NameID at the IdP (e.g. persistent, email, or
        unspecified) does *not* cause the SessionNotFound error, so this
        is another possible solution.</p>
      <p>Cheers</p>
      <p>Martin<br>
      </p>
      <br>
      <div class="moz-cite-prefix">On 21.04.2017 09:23, Martin Haase
        wrote:<br>
      </div>
      <blockquote
        cite="mid:b5877558-d6b7-4c01-2c3e-fac0b0890210@DAASI.de"
        type="cite">
        <pre wrap="">Hi again Scott,

thinking about it a second time, mitigating the error message about this
would be helpful, because sharing accounts is what people do. Because
this is actually common in our project, I think we will switch to the
"Simple Logout", which seems work regardless.

Thanks again,

Martin


On 20.04.2017 19:19, Cantor, Scott wrote:
</pre>
        <blockquote type="cite">
          <pre wrap="">But just glancing at the code, I could imagine some less ambitious changes that might address your specific issue because that's more about the reverse mapping step.
</pre>
        </blockquote>
        <br>
        <fieldset class="mimeAttachmentHeader"></fieldset>
        <br>
      </blockquote>
      <br>
      <pre class="moz-signature" cols="72">-- 
Dr. Martin Haase, Solutions Engineer

DAASI International GmbH        
Europaplatz 3                   
D-72072 Tübingen                
Germany                    

phone: +49 7071 407109-0
fax:   +49 7071 407109-9  
email: <a class="moz-txt-link-abbreviated" href="mailto:martin.haase@daasi.de" moz-do-not-send="true">martin.haase@daasi.de</a>
web:   <a class="moz-txt-link-abbreviated" href="http://www.daasi.de" moz-do-not-send="true">www.daasi.de</a>

Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz
</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
Dr. Martin Haase, Solutions Engineer

DAASI International GmbH        
Europaplatz 3                   
D-72072 Tübingen                
Germany                    

phone: +49 7071 407109-0
fax:   +49 7071 407109-9  
email: <a class="moz-txt-link-abbreviated" href="mailto:martin.haase@daasi.de">martin.haase@daasi.de</a>
web:   <a class="moz-txt-link-abbreviated" href="http://www.daasi.de">www.daasi.de</a>

Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz
</pre>
  </body>
</html>