IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Can ISAM handle Target Application with infinite Idle Session Timeout

    Posted Sun February 23, 2020 04:07 AM
    Hi Folks,

    I came across an application to be integrated with ISAM for SSO. SSO is achieved and rolled out to production. Then, got to know "application is having a business requirement to have infinite idle session timeout".
    Where as ISAM has idle session timeout set as per access control policy. Due to this users are getting challenged to re authenticate when idle session timeout value is met. This is not acceptable to business. 

    Interesting part is : This application is Fraud Management System  and Engineers continuously monitor the alerts on big screens. Therefore, they need infinite idle session. 

    Is there a way in ISAM to exclude this application to have infinite idle timeout. I can not change ISAM Idle session timeout value as per policy.

    Is there any junction specific configuration we can try or any other please. 

    Thanks,
    Usman

    ------------------------------
    UsmanAli Shaik
    ------------------------------


  • 2.  RE: Can ISAM handle Target Application with infinite Idle Session Timeout

    Posted Mon February 24, 2020 08:50 AM
    Any help here please

    ------------------------------
    UsmanAli Shaik
    ------------------------------



  • 3.  RE: Can ISAM handle Target Application with infinite Idle Session Timeout

    Posted Mon February 24, 2020 09:02 AM
    Is this monitoring done through a browser? Maybe you can use a 'refresh' plugin (e.g. auto refresh for chrome) in the monitoring station's browser, and hence have no need to make such an exclusion.

    KR

    Tim

    ------Original Message------

    Hi Folks,

    I came across an application to be integrated with ISAM for SSO. SSO is achieved and rolled out to production. Then, got to know "application is having a business requirement to have infinite idle session timeout".
    Where as ISAM has idle session timeout set as per access control policy. Due to this users are getting challenged to re authenticate when idle session timeout value is met. This is not acceptable to business. 

    Interesting part is : This application is Fraud Management System  and Engineers continuously monitor the alerts on big screens. Therefore, they need infinite idle session. 

    Is there a way in ISAM to exclude this application to have infinite idle timeout. I can not change ISAM Idle session timeout value as per policy.

    Is there any junction specific configuration we can try or any other please. 

    Thanks,
    Usman

    ------------------------------
    UsmanAli Shaik
    ------------------------------


  • 4.  RE: Can ISAM handle Target Application with infinite Idle Session Timeout

    Posted Mon February 24, 2020 09:58 AM

    Nothing in the junction... Closest I'm aware of is as suggested in this blog post, but that is a per session EAI which would require a code change:   https://philipnye.com/2015/11/26/advanced-isam-session-timeout-capabilities/

    But Tim's suggestion seems to make the most sense.



    ------------------------------
    Kurt Green
    ------------------------------



  • 5.  RE: Can ISAM handle Target Application with infinite Idle Session Timeout

    Posted Wed February 26, 2020 02:27 AM
    Good mornings Dears,

    Thanks to both of you. Will work on these and try to propose best feasible.

    Appreciate the help in this community.

    Thanks,
    Usman

    ------------------------------
    UsmanAli Shaik
    ------------------------------