> People don't understand SSO and have no idea about
> the consequences. You should follow the recommended logout procedure from
> the wiki [1]

How true.  Even folks who are very knowledgeable about SSO and CAS
have a hard time deciding what _should_ happen when they click the
logout button on a CAS enabled application.  Some folks think "I just
want to end _this_ application."  Others argue that if you end only a
single application, you're only a back button away from re-entering
assuming your SSO session is still active.  I think the best practice
tries to strike a balance with a fairly clear explanation of what has
happened and options.  I'm open to the idea we could do better though.

M

-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-user

Reply via email to