<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div>Hi Chad,</div><div><br></div><div>I know that next question is not related to the idp but, have you (or anybody) known any case where by any chance, clicking on the logout button on the SP (Google Apps) the session has not been invalidated? I asked this because I'm worry that the single logout at the end won't work because of SP fault (Google Apps)</div><div><br></div><div>Hi Dhivakaran, I based my code from here: <a href="http://shibboleth.1660669.n2.nabble.com/Forwarding-authentication-request-error-404-ExternalAuth-SOLVED-td7310618.html#a7316204">http://shibboleth.1660669.n2.nabble.com/Forwarding-authentication-request-error-404-ExternalAuth-SOLVED-td7310618.html#a7316204</a> </div><div><br></div><div>Thxs</div><div><br></div><div>Cheers.</div><br><div><div>On Aug 9, 2012, at 7:50 PM, Chad La Joie <<a href="mailto:lajoie@itumi.biz">lajoie@itumi.biz</a>> wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">That's up the SP. The IdP has no ability to destroy the SP's session.<br><br>On Thu, Aug 9, 2012 at 8:48 PM, Mark O'Quinn <<a href="mailto:mark1oquinn@gmail.com">mark1oquinn@gmail.com</a>> wrote:<br><blockquote type="cite">Hi Chad,<br><br>Thank for the quick response.<br><br>Yes, I'm asking that, and specially related to the single logout. I don't want to show to the user about closing the browser but to be sure no session is kept with the service provider. is that correct?<br><br>Thanks again<br><br>Cheers.<br><br><br>On Aug 9, 2012, at 7:42 PM, Chad La Joie <<a href="mailto:lajoie@itumi.biz">lajoie@itumi.biz</a>> wrote:<br><br><blockquote type="cite">I'm not 100% sure what you're asking. I think you're asking "if I<br>clear all the cookies, can I be sure the IdP won't find some existing<br>session for the user?". If that's the case, then yes, you can be sure<br>of that. No cookie, no session.<br><br>On Thu, Aug 9, 2012 at 8:24 PM, Mark O'Quinn <<a href="mailto:mark1oquinn@gmail.com">mark1oquinn@gmail.com</a>> wrote:<br><blockquote type="cite">Hi All,<br><br>I've configured Shibboleth idp using external authentication (forceAuth =<br>"true" and isPassive = "false") with google Apps and I've modified the<br>idp.war to include some extra code (to catch the logout process with a<br>personalized filter).<br><br>When I logout from Google I'm redirected to the idp, here I delete all the<br>cookies (by using the filter I created). Now, I don't close the browser and<br>instead I go to gmail and try to login and I'm redirected to the idp to<br>authenticate again (which is something I want to accomplish) my question is,<br>can I rely on this and not tell the user to close the browser?<br><br>I have tested in several browsers and I have always had to reauthenticate<br>without closing the browser.<br><br>Thank you for all your help.<br><br>Cheers.<br><br>--<br>To unsubscribe from this list send an email to<br><a href="mailto:dev-unsubscribe@shibboleth.net">dev-unsubscribe@shibboleth.net</a><br></blockquote><br><br><br>--<br>Chad La Joie<br><a href="http://www.itumi.biz">www.itumi.biz</a><br>trusted identities, delivered<br>--<br>To unsubscribe from this list send an email to dev-unsubscribe@shibboleth.net<br></blockquote><br>--<br>To unsubscribe from this list send an email to <a href="mailto:dev-unsubscribe@shibboleth.net">dev-unsubscribe@shibboleth.net</a><br></blockquote><br><br><br>-- <br>Chad La Joie<br><a href="http://www.itumi.biz">www.itumi.biz</a><br>trusted identities, delivered<br>--<br>To unsubscribe from this list send an email to dev-unsubscribe@shibboleth.net<br></blockquote></div><br></body></html>