Logout/SLO Docs

Cantor, Scott cantor.2 at osu.edu
Fri Dec 11 09:56:35 EST 2015


On 12/11/15, 7:41 AM, "dev on behalf of Marvin Addison" <dev-bounces at shibboleth.net on behalf of marvin.addison at gmail.com> wrote:



>I'm planning to do the docs today, but it occurred to me during planning that these are mostly design documents. Are there any notable configuration points in general? Ensuring idp.session.trackSPSessions = true is the only thing I can think of. A brief discussion of metadata requirements might be warranted as well.

There are two properties involved for SAML, that one and the secondaryIndexing property (can't recall the name offhand). I split that precisely so that CAS-only logout wouldn't require the extra overhead.

There are probably a couple of other logout properties. I think there's one controlling whether SAML requests have to be signed or not.

Beyond that, it's just outlining the views involved so people know what to customize. Given the bug, I would also highlight that and the fix so that if there are early experimenters they know how to patch it for now.

>We might want to provide a description of the functionality from a user's perspective, but I'm unclear where that should go. I don't see that we have any documentation about how to _use_ the software, which is probably the best context. I suppose it could live as front matter in the design docs. Thoughts?

If you mean end users, no, we haven't normally done that, but I would probably just include it as a short section in a LogoutConfiguration topic that covers the rest of the above material.

I also have to add some material on the difference between the SLO endpoint and the /idp/profile/Logout endpoint, and the various metadata implications of using this, of which there are several.

-- Scott



More information about the dev mailing list