Digital identity systems almost universally support end-users logging into 
applications and many also support logging out of them.  But while login is 
reasonable well understood, there are many different kinds of semantics for 
"logout" in different use cases and a wide variety of mechanisms for effecting 
logouts.

I led a discussion on the topic "What Does Logout Mean?" at the 2018 OAuth 
Security Workshop<http://st.fbk.eu/osw2018> in Trento, Italy, which was held 
the week before IETF 101<https://www.ietf.org/how/meetings/past/101/>, to 
explore this topic.  The session was intentionally a highly interactive 
conversation, gathering information from the experts at the workshop to expand 
our collective understanding of the topic.  Brock 
Allen<https://brockallen.com/about/> - a practicing application security 
architect (and MVP for ASP.NET/IIS) - significantly contributed to the 
materials used to seed the discussion.  And Nat 
Sakimura<https://nat.sakimura.org/about-me/> took detailed notes to record what 
we learned during the discussion.

Feedback on the discussion was uniformly positive.  It seemed that all the 
participants learned things about logout use cases, mechanisms, and limitations 
that they previously hadn't previously considered.

Materials related to the session are:

  *   Presentation used to bootstrap the discussions 
(pptx<http://self-issued.info/presentations/What_Does_Logout_Mean_Presentation.pptx>)
 
(pdf<http://self-issued.info/presentations/What_Does_Logout_Mean_Presentation.pdf>)
  *   Notes from the 
session<https://bitbucket.org/openid/connect/wiki/What%20Does%20Logout%20Mean%3F>
  *   Workshop submission 
(pdf<http://self-issued.info/papers/What_Does_Logout_Mean.pdf>)
  *   OpenID Connect issue "Create a document explaining "single logout" 
semantics<https://bitbucket.org/openid/connect/issues/984/create-a-document-explaining-single-logout>"

                                                       -- Mike

P.S. This note was also posted at http://self-issued.info/?p=1804 and as 
@selfissued<https://twitter.com/selfissued>.
_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to