Idle timeout management for non-Siteminder OIDC application
search cancel

Idle timeout management for non-Siteminder OIDC application

book

Article ID: 370199

calendar_today

Updated On:

Products

SITEMINDER CA Single Sign On Agents (SiteMinder) CA Single Sign On Federation (SiteMinder) CA Single Sign On Secure Proxy Server (SiteMinder)

Issue/Introduction

Is it possible to have Siteminder manage the idle timeout for an OIDC application that is not protected by Siteminder?  The OIDC application is using JWT tokens.  

Environment

All versions

Resolution

No.  In order for Siteminder to manage sessions, those sessions must be Siteminder sessions.  In this instance the application will need it's own session management since Siteminder is not being used for its session management.  When sessions are created and managed with Siteminder, tracking and enforcing idle timeouts is a core feature.