<div dir="ltr">And my plan was to run a short 30 minute window to minimize that, until I realized the reauth redirect was interfering with non-GET operations in our app.  So I've been forced to turn it up.<div><br></div><div>I'm currently using the SP as a auth proxy in front of another app. As I understand the model there will always be a delay between disabling the user in the IdP and having their sessions expire in the SP as the SP has it's own sessions.  This can me minimized, but not eliminated, with low lifetimes but that kills the user experience with frequent redirects to the IdP.  So, in my opinion after several days of pondering this problem, a longer session is better for user experience but some sort of administrative kill switch is needed.  I think that's going to be the best tradeoff between usability and security.</div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><span style="font-size:12.8px">--Tom Noonan II</span><br></div></div></div></div></div></div>
<br><div class="gmail_quote">On Wed, Feb 21, 2018 at 8:42 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Tom Noonan <<a href="mailto:tom@joinroot.com">tom@joinroot.com</a>> [2018-02-21 14:37]:<br>
> the default session lifetime is 8h (the default), then there is an<br>
> 8h window in which someone could be disabled in the IdP but still<br>
> access services as their service session is valid.<br>
<br>
Seems to me you're saying that your own session lifetime is to big a<br>
window of opportinty for you.<br>
<span class="HOEnZb"><font color="#888888"><br>
-peter<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br></div>