specifying logout endpojnt at the IDP

Peter Schober peter.schober at univie.ac.at
Wed Jun 13 22:09:28 BST 2012


* Steven Carmody <Steven_Carmody at brown.edu> [2012-06-13 19:59]:
> Presumably, an SP, if it so desired, could complete its own logout
> sequence by redirecting to this url at an IDP ....

You of course know that this leaves all the other SPs and applicatons
the user's browser has sessions with untouched and hence vulnerable,
by creating a false sense of security ("I did logout, so I'm good").

You can put whatever extensions you want into metadata but I doubt it
makes much sense to create a metadata extension for proprietary logout
requests and have people implement support for your metadata extension.
-peter


More information about the users mailing list