Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SAML2 SessionNotOnOrAfter support #2109

Closed
hauntingEcho opened this issue Jan 18, 2018 · 5 comments · Fixed by wso2/carbon-identity-framework#2225 or wso2-extensions/identity-inbound-auth-saml#226

Comments

@hauntingEcho
Copy link

Description:
support for SAML2's SessionNotOnOrAfter property of the would be useful for enforcing an idle session timeout on Service Providers, and ensuring that service providers will refresh from the IdP within that timeframe to prevent an idle timeout at the IdP.

Copied from the plugin repo, as this one seems to get more attention:
wso2-extensions/identity-inbound-auth-saml#165

Suggested Labels:
Component/SAML, Affected/5.4.0

@LahiruLS
Copy link

@lemoinem
Copy link

Sorry to revive an old PR, but this is the only mention of this feature I could find anywhere...

How is this configurable in WSO2 IS 5.10.0 ?
I can find no documentation anywhere and no mention of it in the carbon UI...
Can this be configured on a per-SP basis or just globally?

@hauntingEcho
Copy link
Author

It's only configurable globally, last I knew: #6366

@lemoinem
Copy link

@hauntingEcho We've tried configuring this within our identity.xml file (using WSO2 IS 5.10.0).
However, it seems to be overwritten, maybe because of the implementation of deployment.toml.
Do you have any idea how this can be configured in WSO2 IS 5.10.0?

@hauntingEcho
Copy link
Author

I changed jobs toward the beginning of the year & haven't really worked with 5.10. Best of luck though!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment