IBM Support

PI57465: OIDC: REMOVE SESSION COOKIE AFTER LOGOUT

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • OIDC session cookie is not removed after logout.  You can still
    see the cookie in the browser after logout.
    

Local fix

  • No
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  IBM WebSphere Application Server users of   *
    *                  OpenID Connect                              *
    ****************************************************************
    * PROBLEM DESCRIPTION: The OpenID Connect Relying Party does   *
    *                      not delete its cookies on logout        *
    ****************************************************************
    * RECOMMENDATION:  Install a fix pack that contains this APAR  *
    ****************************************************************
    The OpenID Connect (OIDC) Relying Party (RP) session cookie,
    OIDCSESSIONID_(clientId), remains after logout.  This cookie
    should be deleted upon logout.
    

Problem conclusion

  • The OIDC Relying Party is updated to support logout through
    the HttpServletRequest.logout() Java API call. This API call
    will clear the LtpaToken2 and any other cookies the OIDC
    RP created.
    
    Note that logout through the deprecated revokeSSOCookies()
    method and through the ibm_security_logout servlet is not
    supported for the OpenID Connect Relying Party.
    
    The fix for this APAR is currently targeted for inclusion in
    fix packs 8.0.0.13 and 8.5.5.10.  Please refer to
    the Recommended Updates page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    
    Keywords: IBMWL3WSS, OIDC
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI57465

  • Reported component name

    WEBS APP SERV N

  • Reported component ID

    5724H8800

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2016-02-17

  • Closed date

    2016-05-24

  • Last modified date

    2016-05-24

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBS APP SERV N

  • Fixed component ID

    5724H8800

Applicable component levels

  • R800 PSY

       UP

  • R850 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
28 April 2022