<div dir="ltr"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Don't, unless you have some odd need for back channel logout and apps that would support it.<br></blockquote><div><br></div><div><div>We have been using Memcache based storage in production, but for our future state, we'd been looking at the JPAStorageService.  That said, I *think* that client side would probably be fine for almost everything we need.</div><div><br></div><div>We do use consent, and may end up using ToU, and I don't want those settings to be browser specific.</div></div><div><br></div><div>We're looking at enabling CAS support, and the comments suggest that it requires server side storage?</div><div><br></div><div>Is this comment in idp.properties no longer accurate?</div><div><br></div><div><div>    # MUST be server-side storage (e.g. in-memory, memcached, database)<br></div><div>    # NOTE that idp.session.StorageService requires server-side storage</div><div>    # when CAS protocol is enabled</div></div><div><br></div><div>Liam</div><div><br></div></div>