[JIRA] Commented: (SSPCPP-403) Facilitate signing Logout messages

bajnokk@idp.protectnetwork.org (JIRA) noreply at shibboleth.net
Tue Nov 15 11:03:25 GMT 2011


    [ https://issues.shibboleth.net/jira/browse/SSPCPP-403?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13708#comment-13708 ] 

bajnokk at idp.protectnetwork.org commented on SSPCPP-403:
-------------------------------------------------------

Scott, thanks for the fix!

What do you mean by testbed? We can exchange metadata, so that you could test the changes yourself by using one of our public test IdPs. If you want us to test, then please specify, what parts of the stack needs to be recompiled.

> Facilitate signing Logout messages
> ----------------------------------
>
>                 Key: SSPCPP-403
>                 URL: https://issues.shibboleth.net/jira/browse/SSPCPP-403
>             Project: Shibboleth SP - C++
>          Issue Type: Improvement
>          Components: SAML 2.0 Logout
>            Reporter: bajnokk at idp.protectnetwork.org
>            Assignee: Scott Cantor
>            Priority: Minor
>             Fix For: 2.5
>
>          Time Spent: 15 minutes
>  Remaining Estimate: 0 minutes
>
> SAML2 Single Logout Profile requires LogoutRequest and LogoutResponse messages to be signed when sent over HTTP Redirect or POST bindings. It can be achieved right now by setting signing="front" or signing="true", but it has a side effect of signing every other message (which is probably unnecessary). If it could be done implicitly (and by default), that could make deploying logout easier.

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira


More information about the commits mailing list