[JIRA] Commented: (SSPCPP-403) Facilitate signing Logout messages

Scott Cantor (JIRA) noreply at shibboleth.net
Tue Nov 15 15:47:25 GMT 2011


    [ https://issues.shibboleth.net/jira/browse/SSPCPP-403?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13709#comment-13709 ] 

Scott Cantor commented on SSPCPP-403:
-------------------------------------

Sorry, I meant the former, me testing against an IdP with a test account. I have a lot of logout related bugs to fix. At some point testing by you would be helpful too, but I can do a lot of it up front.

I'll send you email directly with some information once I have a testbed that's publically accessible.

> Facilitate signing Logout messages
> ----------------------------------
>
>                 Key: SSPCPP-403
>                 URL: https://issues.shibboleth.net/jira/browse/SSPCPP-403
>             Project: Shibboleth SP - C++
>          Issue Type: Improvement
>          Components: SAML 2.0 Logout
>            Reporter: bajnokk at idp.protectnetwork.org
>            Assignee: Scott Cantor
>            Priority: Minor
>             Fix For: 2.5
>
>          Time Spent: 15 minutes
>  Remaining Estimate: 0 minutes
>
> SAML2 Single Logout Profile requires LogoutRequest and LogoutResponse messages to be signed when sent over HTTP Redirect or POST bindings. It can be achieved right now by setting signing="front" or signing="true", but it has a side effect of signing every other message (which is probably unnecessary). If it could be done implicitly (and by default), that could make deploying logout easier.

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira


More information about the commits mailing list