<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<font face="Helvetica, Arial, sans-serif">Are my assumptions correct
that this is not a Shibboleth IdP issue but a SAML issue?<br>
<br>
Thanks,<br>
Don<br>
</font><br>
<div class="moz-cite-prefix">On 3/15/23 11:47 AM, Cantor, Scott
wrote:<br>
</div>
<blockquote type="cite" cite="mid:E9355B84-2166-43AC-A420-BC50A255115C@osu.edu">
<pre class="moz-quote-pre" wrap="">CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.
________________________________
Since logout is and will probably always be hopeless, there are two options, one realistic and one only semi-practical.
The primary tool is the option on the password login form to signify it's a shared machine. That requires user choice but it's the only practical way. That prevents SSO via a client signal.
The other option is controlling the network from which the machines connect and scripting the system to prevent login reuse for them based on the client address. That is limited in scope and ultimately has never gone very far for me.
I don't know of any other practical means of identifying shared machines that could be trusted.
-- Scott
</pre>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</body>
</html>