Skip to Content.
Sympa Menu

shibboleth-dev - Re: [Shib-Dev] Viability of SSL/TLS Session IDs usage for application Session IDs

Subject: Shibboleth Developers

List archive

Re: [Shib-Dev] Viability of SSL/TLS Session IDs usage for application Session IDs


Chronological Thread 
  • From: Kristof Bajnok <>
  • To:
  • Subject: Re: [Shib-Dev] Viability of SSL/TLS Session IDs usage for application Session IDs
  • Date: Wed, 9 Feb 2011 16:48:24 +0100
  • Organization: NIIF Institute

On Wednesday 09 February 2011 15:52:40 Chad La Joie wrote:
> Doing this seems like it would address all the aforementioned issues
> and obviate the need for a session cookie

How does the TLS session compare to the stateless HTTP? Browser differences
put
aside, when should TLS session IDs be regenerated?

For logout, the IdP must maintain the associated SP list for each user, and
at
the moment it uses the session for that.

Kristof



Archive powered by MHonArc 2.6.16.

Top of Page