grouper-users - RE: [grouper-users] Grouper UI default timeout in ITAP container
Subject: Grouper Users - Open Discussion List
List archive
- From: "Hyzer, Chris" <>
- To: Bill Thompson <>
- Cc: " Mailing List" <>
- Subject: RE: [grouper-users] Grouper UI default timeout in ITAP container
- Date: Mon, 10 Jun 2019 15:28:01 +0000
For our webapps we kill the java session and redirect to the SP logout, with a redirect to let the user globally logout…
yeah, I hear you on the shorter than an hour timeout… I think administrative apps have workers at a desk and might be ok with an hour, but yeah, if someone uses it at a public computer and doesn’t log out, that would be bad…
From: Bill Thompson <>
Interesting. When the user hits the log out button in Grouper, what happens to the SP session?
OWASP offers this advice regarding inactivity timeouts: "The most appropriate timeout should be a balance between security (shorter timeout) and usability (longer timeout) and heavily depends on the sensitivity level of the data handled by the application. For example, a 60 minute log out time for a public forum can be acceptable, but such a long time would be too much in a home banking application (where a maximum timeout of 15 minutes is recommended). In any case, any application that does not enforce a timeout-based log out should be considered not secure, unless such behavior is required by a specific functional requirement."
Best, Bill
On Mon, Jun 10, 2019 at 7:06 AM Hyzer, Chris <> wrote:
|
- Re: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, (continued)
- Re: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Bryan Wooten, 06/07/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Black, Carey M., 06/08/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/08/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Redman, Chad, 06/08/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Redman, Chad, 06/08/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/08/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Black, Carey M., 06/08/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/08/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/09/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/09/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Gettes, Michael, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Gettes, Michael, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/12/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/12/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/09/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/09/2019
- Re: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Bryan Wooten, 06/07/2019
Archive powered by MHonArc 2.6.19.