<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Hi Ray,</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Thanks for sharing the link.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
There is no redirect to the IdP on the logout button .</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
I am having the team look at the force login option and its impact now.</div>
<div id="Signature" class="elementToProof">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="direction: ltr; text-align: left; text-indent: 0px; background-color: white; margin: 0px; font-family: Arial, Helvetica, sans-serif; font-size: 10pt; color: black;">
Regards,</div>
<div class="elementToProof" style="direction: ltr; text-align: left; text-indent: 0px; background-color: white; margin: 0px; font-family: Arial, Helvetica, sans-serif; font-size: 10pt; color: black;">
<br>
</div>
<div class="elementToProof" style="direction: ltr; text-align: left; text-indent: 0px; background-color: white; margin: 0px; font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(12, 100, 192);">
<b>Amit Dongaonkar</b></div>
<div class="elementToProof" style="direction: ltr; text-align: left; text-indent: 0px; background-color: white; margin: 0px; font-family: Arial, Helvetica, sans-serif; font-size: 10pt; color: black;">
<br>
</div>
</div>
<div id="appendonsend"></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="display: inline-block; width: 98%;">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>From:</b> users <users-bounces@shibboleth.net> on behalf of Ray Bon via users <users@shibboleth.net><br>
<b>Sent:</b> Friday, April 17, 2026 1:44 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Ray Bon <rbon@uvic.ca><br>
<b>Subject:</b> Re: Question regarding user logout workflow </div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<table align="left" cellspacing="0" cellpadding="0" border="0" style="direction: ltr; width: 100%;">
<tbody>
<tr>
<td style="direction: ltr; background-color: rgb(255, 0, 0); padding: 5pt 2pt;"></td>
<td style="direction: ltr; padding: 5pt 4pt 5pt 12pt; width: 100%;">
<div style="direction: ltr; color: rgb(0, 0, 0);"><span style="color: red;"><b>CAUTION :</b></span>
<span style="color: red;">EXTERNAL SENDER | Proceed carefully when clicking links or opening attachments.</span></div>
</td>
</tr>
</tbody>
</table>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Amit,</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Are you sure there is no redirect to the IdP after the logout button is pressed?</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Logout in the application is separate from logout in the IdP. Unless the IdP logout endpoint is reached, the IdP session will stay valid (for 5h as you noted).</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
You could force login, but that has its own compromises [1] </div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Ray</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
[1] <a href="https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2076410043/ForceAuthn" data-auth="NotApplicable" id="OWAbaa49875-e349-942c-9926-52feda6611df" class="OWAAutoLink">
https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2076410043/ForceAuthn</a></div>
<div id="x_appendonsend"></div>
<hr style="direction: ltr; display: inline-block; width: 98%;">
<div id="x_divRplyFwdMsg">
<div style="direction: ltr; font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<b>From:</b> users <users-bounces@shibboleth.net> on behalf of Amit Dongaonkar via users <users@shibboleth.net><br>
<b>Sent:</b> April 17, 2026 08:37<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Amit Dongaonkar <amitd@nitssolutions.com><br>
<b>Subject:</b> Question regarding user logout workflow</div>
<div style="direction: ltr;"> </div>
</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
Hi Group,</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
I have a question about the user logout workflow. </div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<br>
</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
We have Shibb SP servicing users coming to our platform. During a penetration testing exercise an observation was raised as follows:</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<br>
</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
When a user hits the logout button on the application he is logged out but when he enters the application URL again in the browser then he is able to get into the application again without get redirected to the IdP for authentication.</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<br>
</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
Looking at the SAML assertion received for the user I see the following</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<saml:AuthnStatement SessionIndex="wcfENW_JyI4mCzIxCTeGEo-oH6."</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
SessionNotOnOrAfter="2026-04-17T20:32:43.689Z"</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
AuthnInstant="2026-04-17T15:02:43.460Z"</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
></div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
So the IdP is saying that the session is valid for roughly 5 hours. </div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<br>
</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
Since the user is trying to access the application as soon as he logs out and its well within 5 hours the application is letting the user in again. Also I see the application sending a auth request to the IdP this time around before letting the user in.</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<br>
</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<b>Question</b>: Is this the right behavior and the observation from the pen testing is not valid, if not, then is there a way to invalidate the session once the user logs out from the application so that he is redirected to the IdP for authentication? </div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<br>
</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
Note that we don't have a Single Logout (SLO) URL from the IdP and I prefer to not use it as it will throw him out of all other applications (that's my understanding).</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<br>
</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
Would appreciate any guidance on this.</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<br>
</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<br>
</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
Thanks </div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
Amit Dongaonkar</div>
<div style="direction: ltr; font-family: "Calibri Light", sans-serif; font-size: 15px; color: rgb(118, 113, 113);">
<br>
</div>
<div style="direction: ltr; line-height: 18px; font-size: 12px; color: rgb(107, 114, 128);">
<span style="color: rgb(17, 17, 17);"><b>CONFIDENTIALITY NOTICE:</b></span> This e-mail and any accompanying document(s) contain confidential information which is privileged and intended only for the addressee hereof. If you are not the intended recipient,
you are hereby notified that any disclosure, copying, distribution or use of this e-mail and/or accompanying document(s) is strictly prohibited. If you have received this e-mail in error, please immediately notify the sender at the above e-mail address.</div>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<title>NITS Email Signature</title>
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/7.0.1/css/all.min.css"><style type="text/css">
@media only screen and (max-width: 620px) {
.container { width: 100% !important; }
.stack { display: block !important; width: 100% !important; }
}
a[x-apple-data-detectors] { color: inherit !important; text-decoration: none !important; }
</style><!-- Confidentiality Notice -->
<div style="font-size:12px; line-height:18px; color:#6b7280;"><strong style="color:#111111;">CONFIDENTIALITY NOTICE:</strong> This e-mail and any accompanying document(s) contain confidential information which is privileged and intended only for the addressee
hereof. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution or use of this e-mail and/or accompanying document(s) is strictly prohibited. If you have received this e-mail in error, please immediately notify
the sender at the above e-mail address. </div>
</body>
</html>