Symantec Access Management

 View Only

About SessionStore (on CA Directory)

  • 1.  About SessionStore (on CA Directory)

    Posted Apr 14, 2023 08:38 AM
     
    I would like to understand a little more about the session store.
    This morning for example I found over 130K objects (objectClass=smSession) all not expired smSessionStatus=0

    One weird thing I've noticed is that I have 3 items, let's say

    smSessionId=value1
    smSessionId=value2
    smSessionId=value3
     
    with different smSessionBlob, mExpoirationTime,ecc..
     
    each has a child (it's a sessionVariable) but the childs are identical: they have same cn and same values ​​on smVariableName and smVariableAttribute

    In this case, the variable was an access token oidc So I'm sure it's exactly the same. How is this thing possible?

    I thought there was exactly one smSessionId for each persistent session.
     
    Is there a way to count persistent siteminder sessions at any given time?
     
    One idea I had was to add a session variable on each persistent session by adding the username/universalId so that I can know how many sessions a given user has (and possibly limit/kill them)
    Thanks in advance
    Marco