Regarding Single Logout

Chad La Joie lajoie at itumi.biz
Wed Aug 10 13:55:40 BST 2011


IdP 2.2.0 is now know to have significant security vulnerabilities.
You shouldn't be using it.

On Wed, Aug 10, 2011 at 08:51, Naveen Davis <naveen.davis at aalto.fi> wrote:
>
> Hi,
>
> I am new to shibboleth and I have been trying to implement single logout
> in shibboleth. I have installed & configured the Hungarian SLO
> Shibboleth Idp (version 2.2.0) on my Ubuntu(version 10.04) machine. The
> Shibboleth SP ( version 2.4.3) is running on CentOS(version 5.5) in
> Vmware. The shibboleth SSO is working fine.But the single logout is not
> working at all and IdP still have an active SSO session after logging
> out. It just displays an error message stating missing endpoint security
> requirements. I have checked the shibd.log file, but no specific error
> message. I have configured the single logout endpoints in Idp metatdata
> as follows
>
>
> <SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
>
> location="https://idp1.example.org/idp/profile/SAML2/Redirect/SLO"
>
> ResponseLocation="https://idp1.example.org/idp/profile/SAML2/Redirect/SLO"/>
>
> <SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
>
> Location="https://idp1.example.org/idp/profile/SAML2/POST/SLO"
>
> ResponseLocation="https://idp1.example.org/idp/profile/SAML2/POST/SLO"/>
>
> <SingleLogoutService
>
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
>
> Location="https://idp1.example.org:8443/idp/profile/SAML2/SOAP/SLO" />
>
>
> I would like to know am I missing any key configurations in Idp and SP
> for enabling single logout. Also is there any good reference on Single
> logout/Hungarian SLO configurations apart from the wiki page.
>
> BR,
> Naveen
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list