Invalidating and configuring end user sessions
End user sessions are automatically invalidated when the maximum time set for the session elapses. As a Remedy Single Sign-On administrator, you can set the end user session maximum time, and when required, invalidate the sessions before they elapse.
For example, you might need to invalidate a session if you have previously set a long period of time as the maximum time for the session, and during this time an end user leaves an organization.
If you have applications which act as OAuth clients and interact with Remedy SSO, the end user sessions token might be valid during a long period of time, and you might also need to invalidate sessions.
When you invalidate an end user session on the Remedy SSO server, the user is not immediately logged out from the integrated applications. The user will be asked to log in on opening an application integrated with Remedy SSO in another browser. The time duration when the user continues to be logged in depends on the logout settings of the Remedy SSO agent.
To view session details
Perform the following steps to view the session details:
- Log in to Remedy SSO Admin Console.
Click the Session tab.
In the Search field, enter the user or realm ID for which you want to view the session details.
The system displays the following information:Field
Description
User ID User ID associated with the session. Realm Realm ID associated with the session. Time Remaining Time remaining for the session. Maximum Session Time Time that was associated for the session. - (Optional) To invalidate/kill a user session, click Delete in the Action column, for the required session.
To invalidate an end user session for AR authentication
- Log in to Remedy SSO Admin Console.
From the menu, click Session.
- On the Session Report page, locate the required session.
- Click Delete in the Action column.
To invalidate an end user session for OAuth authentication
- Log in to Remedy SSO Admin Console.
From the menu, click OAuth2.
- On the Server Configuration page, click the Tokens tab.
- Locate the required token.
- Click Delete in the Action column.
Comments
Log in or register to comment.