JBoss SSO is not invalidating all sessions tied to an SSO cookie upon logout or invalidation

Solution Verified - Updated -

Issue

  • We use JBoss single sign on. When we call request.logout(), the application sessions tied to that SSO entry are not invalidated like we would expect.
  • We use unclustered SingleSignOn with a <distributable/> application. When we call session.invalidate() or request.logout() on an application session, all other application sessions tied to that corresponding SSO entry are not invalidated like we would expect.

Environment

  • JBoss Enterprise Application Platform (EAP) 6.x

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.