Well there is a zimbraAdminAuthTokenLifetime for each user and in the default CoS. This is a default 12 hours set which is a bit high if you ask me. There is no value for idle timeout like the client UI has, i.e. zimbraMailIdleSessionTimeout. So the admin UI doesn't seem to log itself out even with AuthTokenLifetime set short. Also I think in the Admin UI the time settings for Session Idle Timeout and AuthToken Lifetime should have a minutes option in the pull down next to it. One hour is quite a long time for idle logout.
Ben |