Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Request for Clarification: Dependency on Third-Party Plugins for Single Logout (SLO) in Atlassian Cr

kam
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
April 25, 2025

Issue Context:
Atlassian Crowd provides robust SSO functionality, but the implementation of ​Single Logout (SLO) appears to require additional configuration or custom development. Based on documentation (e.g., Crowd Data Center 3.4 SSO 2.0), while Crowd supports cross-domain SSO and centralized authentication, there is no explicit guidance on native SLO capabilities. For example:

  • When users log out of Crowd, applications like Jira or Confluence may retain active sessions, indicating incomplete SLO.
  • Existing solutions (e.g., session validation via SSOCookieFilter or SAML integration) require custom code or third-party plugins.

Key Questions:

  1. Does Crowd natively support SLO without relying on third-party plugins or manual implementation (e.g., SAML/CAS protocol extensions)?
  2. If SLO is not natively supported, are there official recommendations for achieving global logout across integrated applications?
  3. Are there plans to enhance Crowd’s SLO capabilities in future releases (e.g., built-in SAML SLO endpoints or automated session termination)?

Relevant Documentation:

  • Crowd SSO 2.0 documentation mentions cross-domain SSO but lacks SLO details.
  • Integration guides (e.g., Microsoft Entra SSO, Bitbucket) emphasize authentication but not logout synchronization.

Suggested Improvements:

  • Provide native SLO workflows (e.g., SAML SLO support or centralized session invalidation).
  • Clarify whether third-party plugins (e.g., SAML IdPs) are mandatory for SLO.

0 answers

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events