Hmm.. these are good questions
<exclusiveDuration> should be the length of the login period. I.e. the user will be logged out automatically when this time expires.
The undocumented stuff in the DTD - appEncryptedCertificate/remoteIpAddr/isViaHeaderSet/checkUser - is probably vestigial, but I have a request into engineering to confirm and/or explicate. We need to cleanup/update the DTD and docs here.
I do know that <logoutAll> is intended to logout all E/M users, and so should not have a deviceName paramter (this is borne out by the DTD.) It definitely looks like the example in the doc is messed up.