SSL authentication and timeout
Novell Cool Solutions: Question & Answer
Q:
Here's our scenario: a user authenticates by logging in to the BorderManager server before browsing and then closes down the browser before the timeout kicks in. He then logs off the PC. Another user logs in to the PC and then opens the browser, still within the timeout.
Will BorderManager require this user to authenticate? If not, is there any way of forcing the authentication to be done when a new user logs on to the PC? If not, this leaves us with a security headache and a large hole in our monitoring and login.
A:
If you're talking about SSL authentication, BorderManager will not require it. There is a logout page, but the user has to go there voluntarily. As far as I know, it can't be automated.Single Sign-on doesn't have that problem. When the user logs out from eDirectory it automatically logs out from the proxy. The only solution I can provide you with is to put the timeout for SSL very short, something like 5 minutes.
Novell Cool Solutions (corporate web communities) are produced by WebWise Solutions. www.webwiseone.com
