Logoff URI doesn't remove the user session from Session Store
search cancel

Logoff URI doesn't remove the user session from Session Store

book

Article ID: 244707

calendar_today

Updated On:

Products

SITEMINDER CA Single Sign On Agents (SiteMinder)

Issue/Introduction

 

When running a Policy Server, when the user performs a complete logout, if the SMSESSION is reinjected in the browser, the browser can still access the protected resource without being redirected to the login page.

 

Environment

 

  Policy Server 12.8SP6a;
  Session Store on MSSQL 
  Web Agent 12.52SP1 on Apache 2.4;

 

Cause

 

Looking at Apache configuration, the Apache instance wasn't configured to run the Web Agent, so the logoff URI cannot be processed.

 

Resolution

 

Installing and configuring the Web Agent solved the issue. Now the Authentication and Logout via the Web Agent is working correctly and indeed the cookie gets invalidated and the session canceled from the Session Store.