The SAML XML.org web site is not longer accepting new posts. Information on this page is preserved for legacy purposes only. For current information on SAML, please see the OASIS Security Services Technical Committee Wiki.
idle timeout?
Forum topic: Submitted by girgen on Mon, 2009-05-11 09:03.
Hi!
Is logout due to idle timeout a part of SAML. I read the specs, and it only says that single logout can be initiated due to timeout, but how would that really work? Wouldn't the IdP have to ask every SP if they agree to logout the user due to timeout?
re: idle timeout
The IdP control's its "session" with the user, so if the IdP has some idle timer, the IdP could send an SLO message to any SPs for which the IdP authenticated the user during the current session.
That said, however, good idle timeout in an SSO environment would require some capabilities that is not currently defined in SAML. These include:
That does not exist in SAML today.
idle timeout?
I don't recall anything in the standard that says logout can be initiated due to timeout or what it would mean, but there is no support in the standard for distributed timeout management.