Next in thread → Next in month →

RE: [saml-dev] Cross domain session timeouts

From
Cahill, Conor P <>
Date
2007-10-09T23:24:47+00:00
ID
Thread
RE: [saml-dev] Cross domain session timeouts
> > 2. Allow IDP to transmit its session requirements to the SP as part
of
> > SAML metadata?
> > (e.g., "send user back to me for reauthentication after 15 minutes
of
> > inactivity")
> >
> > This is actually carried in the authentication assertion.  The
> > SessionNotOnOrAfter attribute on the AuthnStatement is the place to
put
> > this.
> 
> No, that's for session lifetime, not idle timeout. There is no way to
deal
> with timeouts in SAML, it's not addressed at all.

Yeah... I just read the "send the user back to me for reauthentication
after
15 minutes"  (leaving off the "of inactivity" in my head).

Sorry.

Conor
Next in thread → Next in month →