[JIRA] Commented: (SSPCPP-403) Facilitate signing Logout messages
Scott Cantor (JIRA)
noreply at shibboleth.net
Tue Nov 15 15:47:25 GMT 2011
[ https://issues.shibboleth.net/jira/browse/SSPCPP-403?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13709#comment-13709 ]
Scott Cantor commented on SSPCPP-403:
-------------------------------------
Sorry, I meant the former, me testing against an IdP with a test account. I have a lot of logout related bugs to fix. At some point testing by you would be helpful too, but I can do a lot of it up front.
I'll send you email directly with some information once I have a testbed that's publically accessible.
> Facilitate signing Logout messages
> ----------------------------------
>
> Key: SSPCPP-403
> URL: https://issues.shibboleth.net/jira/browse/SSPCPP-403
> Project: Shibboleth SP - C++
> Issue Type: Improvement
> Components: SAML 2.0 Logout
> Reporter: bajnokk at idp.protectnetwork.org
> Assignee: Scott Cantor
> Priority: Minor
> Fix For: 2.5
>
> Time Spent: 15 minutes
> Remaining Estimate: 0 minutes
>
> SAML2 Single Logout Profile requires LogoutRequest and LogoutResponse messages to be signed when sent over HTTP Redirect or POST bindings. It can be achieved right now by setting signing="front" or signing="true", but it has a side effect of signing every other message (which is probably unnecessary). If it could be done implicitly (and by default), that could make deploying logout easier.
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the commits
mailing list