<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p>Hello,<br>
      <br>
      We have activated SLO in IdP3.3 which delegates authentication
      process to CAS server.<br>
      However, we notice that when we sign out from web application, the
      shibboleth session is destroyed but the CAS TGT ticket still
      exist.<br>
      That cause to get access to web app with previous session.<br>
    </p>
    <p>How can we ensure that both Shibboleth session and CAS ticket are
      destroyed while signed out?<br>
    </p>
    <p>Here is SLO configuration in idp.properties :</p>
    <p><i>idp.session.trackSPSessions = true</i><i><br>
      </i><i>idp.session.secondaryServiceIndex = true</i><i><br>
      </i><i>idp.session.defaultSPlifetime = PT2H</i><i><br>
      </i><i>idp.session.slop = PT0S</i><i><br>
      </i></p>
    <i>idp.logout.elaboration = true</i><i><br>
    </i><i>idp.logout.authenticated = false</i>
    <p>Thanks in advance.<br>
    </p>
    <pre class="moz-signature" cols="72">-- 
Cordialement

Marc SAHIN
Administrateur Systèmes
Pôle Système  - DSI - Université Lumière Lyon 2
04 78 77 26 66
</pre>
  </body>
</html>