<?xml version="1.0"?>
<rss version="2.0">
<channel>
<title>Thycotic Community - Secret Server - Closing tab in Internet Explorer circumvents the timeout value - Messages</title>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=244</link>
<description>Thycotic Community - Secret Server - Closing tab in Internet Explorer circumvents the timeout value - Messages</description>
<language>en-us</language>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>
<generator>Jitbit AspNetForum</generator>
<pubDate>Tue, 30 Mar 2010 09:47:17 GMT</pubDate>
<lastBuildDate>Tue, 30 Mar 2010 09:47:17 GMT</lastBuildDate>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=244</link>
<title>Message from David</title>
<description><![CDATA[Secret Server 7.0 deprecates the aforementioned Web.config file change. We moved the forms node into a separate "web-auth.config" file located in your Secret Server directory. If you previously changed the timeout value in Web.config, you will have to similarly alter "web-auth.config" after updating. Future updates will not overwrite this file.<br/><br/>David<br/>Thycotic Support]]></description>
<pubDate>Tue, 30 Mar 2010 09:47:17 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=244</link>
<title>Message from Deane C</title>
<description><![CDATA[That worked a treat, thank you Scott. Changed the line to:-<br/><br/>forms name="ihawu" protection="All" timeout="15" slidingExpiration="true" loginUrl="Login.aspx"<br/><br/>to fall in line with the inactivity timeout of 15 Minutes. Restarted the web server, not sure if I needed to do this or not.<br/><br/>Deane]]></description>
<pubDate>Wed, 13 Jan 2010 01:30:39 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=244</link>
<title>Message from Scott</title>
<description><![CDATA[Hello Deane,<br/><br/>There is a server-side setting for this.<br/><br/>First, you would need to disable the Remember Me feature from the Admin Configuration screen. <br/><br/>Then lower the session timeout in the web.config file. The timeout is in minutes and will look like the line below. (Updated to 5 minutes)<br/><br/>forms name="ihawu" protection="All" timeout="1000000" slidingExpiration="true" loginUrl="Login.aspx"<br/><br/>Setting this timeout will ignore the browser session, and the user will have to login after the timeout period elapses. The timeout begins when the user session becomes inactive.<br/><br/><br/>best,<br/>Scott<br/>Thycotic Support]]></description>
<pubDate>Tue, 12 Jan 2010 11:50:20 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=244</link>
<title>Message from Deane C</title>
<description><![CDATA[Hi,<br/><br/>I have what is hopefully an easy question. If I close a tab on Internet Explorer without loggin out of Secret Server and then open a new tab later in the day it will connect me straight through to secret server without logging in. I have a timeout value set to 15 minutes which works fine if you leave the tab logged in. I guess this is something that IIS controls but I'm not sure where to start looking.<br/><br/>Any help would be very much appreciated as this has been spotted by our security guys.<br/><br/>Thanks<br/><br/>Deane]]></description>
<pubDate>Tue, 12 Jan 2010 08:50:23 GMT</pubDate>
</item>
</channel>
</rss>
