<div dir="ltr"><div>This is a fork off my other thread "Manually force Shibboleth SP to expire/invalidate all sessions" and is following up from the context there. I have some architectural questions about the V3 client session support to be added under <a href="https://issues.shibboleth.net/jira/browse/SSPCPP-775">https://issues.shibboleth.net/jira/browse/SSPCPP-775</a> (Please correct me if this is the wrong ticket).</div><div><br></div><div>Per the other thread, and if my understanding is correct, this feature will allow sessions to move from one SP to another. I have a couple questions I'd like to voice to understand how this will be set up and impact our security stance:</div><div><br></div><div>- How will one SP know the session is valid from another SP?</div><div><br></div><div>- Will something (a cert I'm guessing) need to be shared between the SPs to group them?</div><div><br></div><div>Please let me know, thank you!</div><div><br></div><div><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><span style="font-size:12.8px">--Tom Noonan II</span><br></div></div></div></div></div></div>
</div>