Módosítások

Single Logout in Shibboleth IdP

799 bájt hozzáadva, 2009. augusztus 18., 11:00
Required changes in IdP API
* SessionNotOnOrAfter
== Required changes in IdP API ==
=== Name identifier caching in IdP session ===In the LogoutRequest the IdP must reference the current user's name identifier. This name identifier is issued as part of the SSO process. In order to efficiently retrieve this information, the IdP should cache the name identifier in the IdP session information object. Associated ticket: [https://bugs.internet2.edu/jira/browse/SIDP-336 SIDP-336] === Session indexing for name identifiers ==={{TODO_EN|AdamOn receiving a LogoutRequest from a session participant, the IdP must be able to retrieve the IdP session associated with the principal. Session participants use the issued name identifier to identify the principal. The IdP session object can be indexed (and then retrieved of course) by any arbitrary unique key, please! so we use the name identifier value to index the session. Associated ticket:)}}[https://bugs.internet2.edu/jira/browse/SIDP-338 SIDP-338] 
== Missing features ==
* Administrative logout
565
szerkesztés

Navigációs menü