<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">2018-04-20 2:25 GMT+02:00 Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span>:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="m_8957820964714609942gmail-">> I did not exactly understand what’s funny. I did not mean that using session<br>
> cookie and a bad behaviour of chrome was a good thing. Not at all. May be<br>
> my explanations were not clear enough.<br>
<br>
</span>I was referring to the fact that you seem to want sessions to survive restarts (and longer), and most people are a lot more concerned abot the fact that sessions tend to survive restarts at all.<br></blockquote><div><br></div><div>Ok, i understand. May be it is not very clear to me what was is stored inside the 
shib_idp_persistent_ss. And if it should be used or not for remember me. But maybe not. And yes, to me, that is a problem that Chrome does not respect specification and it is even more problematic that it does not even warn or inform about it.<br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<span class="m_8957820964714609942gmail-"><br>
> Do you think the remember me should be implemented on idp side or sp<br>
> side ? And is this feature something you have think to implement on<br>
> Shibboleth ?<br>
<br>
</span>I haven't ever given it any thought, but if an app wants somebody to be logged into it forever, that's probably something an app could handle itself.<br>
<br>
Either end can be configured with extremely long session lifetimes anyway, but they're both programmed explicitly to use session cookies, not persistent ones.<br>
<div class="m_8957820964714609942gmail-HOEnZb"><div class="m_8957820964714609942gmail-h5"><br></div></div></blockquote><div><br></div><div>If i had to implement "remember me feature" on the idp or sp, i would not use extremely long lifetimes session on the server. I would rather use the way Spring security is implementing it :
<a href="http://jaspan.com/improved_persistent_login_cookie_best_practice" target="_blank">http://jaspan.com/improved_<wbr>persistent_login_cookie_best_<wbr>practice</a>

<br></div><div><br></div><div>What are the entry points in Shibboleth to use the Spring Security implementation ? Does someone already do that ?<br></div><div><br></div><div>Thanks<br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="m_8957820964714609942gmail-HOEnZb"><div class="m_8957820964714609942gmail-h5">
-- Scott<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/co<wbr>nfluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a></div></div></blockquote></div><br></div></div>