logout service in saml 2.0
Hello,
I enabled the saml2.0 authentication with handle logout service in AEM, it works well for user authentication, but I found a sign out problem. When I tried to sign out from AEM, it will redirect me to the logout url page which I configured in IDP, however i don't think it is a real sign out, because when I close the browser and open a new browser, it doesn't require me to provide the username/password again even through the IDP login page displayed, it seems like browser will remember my credential in the cookie?
How can I resolve this problem? Do I need to write some code to handle this by myself or there is some code can be reused in AEM or need IDP to set expire cookie time? I want to have this function: Once user click sign out in AEM, AEM will do the real signout (remove session or cookie?) so that user need to provide username/password for saml authentication again. It seems like enable the saml in AEM will break the original OOTB sign out function.
Owen Wang