NIIF SLO Questions

Peter Williams pwilliams at rapattoni.com
Tue Oct 11 18:09:24 BST 2011


I don't know of a single instance in US real estate, after 5+ years of 100+ SSO deployments by 10 or more vendors, that does otherwise. 

Our own experiments with SAML2 SLO fell into internal disarray; and were dis-enabled. They didn't even work "naturally" between one SP and one IDP. 

The model of SLO that comes with Microsoft WIF best practices looks  a little more promising (as it leverages the hypermedia security model of https and the SSL handshakes of the underlying SSL protocol, given a source document delivered over https). I put this SLO infrastructure into our production code, but have yet to find the courage to raise the question of whether it should be turned on. We specifically left the UI to be decided later, as results are returned from the field. Hopefully, as folks see it working fine on Windows live with a billion users, etc, we can persuade them to "just do the same thing" as works at the Live IDP. We don't need to do anything more for the public than what works at Google, Yahoo, live, facebook. This is the gold standard for consumers, at this point.

-----Original Message-----
From: dev-bounces at shibboleth.net [mailto:dev-bounces at shibboleth.net] On Behalf Of Cantor, Scott

The UI is entirely subjective. I'm sure there are people who think hitting logout at an SP should leave you, well, at the SP.



More information about the dev mailing list