<div dir="ltr">> <span style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">Sure, that's all easy to agree with, but since administrative logout</span><br style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial"><span style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">doesn't exist (as explained by Scott) and is unlikely to exist going</span><br style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial"><span style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">forward (ditto) not sure what you expect.</span><div><span style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline"><br></span></div><div><span style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">My expectation is to discuss it and see if it can be added, as the planned V3 change Scott mentioned will break my current workaround. I found <a href="https://issues.shibboleth.net/jira/browse/SSPCPP-775">https://issues.shibboleth.net/jira/browse/SSPCPP-775</a> which appears to be in the discovery and requirements phase. So my intention is to bounce this idea off Scott, who appears to be the owner of this code, and see what he says. If the planned implementation uses timestamped sessions, which I imagine it would, then implementing this feature might be very easy and something I could submit a pull request for in the future.</span></div><div><span style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline"><br></span></div><div><span style="font-size:12.8px">I'm also unfamiliar with <span style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:12.8px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">the Shibboleth consortium and how to join it to officially raise my concerns, so by voicing my concerns here I'm also learning what I need to do to follow this project's flows. So I guess my expectation is to discuss this need with the community, see what those who know more about this than I do say, and learn how to get it things considered that don't currently exist.</span></span></div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><span style="font-size:12.8px">--Tom Noonan II</span><br></div></div></div></div></div></div>
<br><div class="gmail_quote">On Wed, Feb 21, 2018 at 9:27 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Tom Noonan <<a href="mailto:tom@joinroot.com">tom@joinroot.com</a>> [2018-02-21 15:02]:<br>
> I'm currently using the SP as a auth proxy in front of another app. As I<br>
> understand the model there will always be a delay between disabling the<br>
> user in the IdP and having their sessions expire in the SP as the SP has<br>
> it's own sessions. This can me minimized, but not eliminated, with low<br>
> lifetimes but that kills the user experience with frequent redirects to the<br>
> IdP. So, in my opinion after several days of pondering this problem, a<br>
> longer session is better for user experience but some sort of<br>
> administrative kill switch is needed. I think that's going to be the best<br>
> tradeoff between usability and security.<br>
<br>
Sure, that's all easy to agree with, but since administrative logout<br>
doesn't exist (as explained by Scott) and is unlikely to exist going<br>
forward (ditto) not sure what you expect.<br>
I guess you can become a member of the Shibboleth consortium and try<br>
to make your voice and arguments heard. (Noone is against having<br>
better security, it's a trade-off in light of restricted dev<br>
resources, complexity of the required changes, other features asked<br>
for, etc.)<br>
<br>
Have you considered using a storage backend that does support<br>
clustering and fail-over properly? Memcache in itself has no<br>
replication, andrepcache seems to be a dead end. Have you tried<br>
replacing your memcached instances with Couchbase Server?<br>
<a href="https://www.couchbase.com/memcached" rel="noreferrer" target="_blank">https://www.couchbase.com/<wbr>memcached</a><br>
The community edition is FLOSS (if I can find the license anywhere)<br>
but if you have no issues paying for Oracle RAC licenses you might of<br>
course consider the Enterprise Edition.<br>
<br>
(I note that SimpleSAMLphp uses replicated memcache for a clustered<br>
session store, and that seems to serve all of the Norwegian Higher Ed<br>
just fine -- they're all using a shared, single IDP instance -- but<br>
SSP has added its own replication layer on top of memcache.)<br>
<span class="HOEnZb"><font color="#888888"><br>
-peter<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br></div>