specifying logout endpojnt at the IDP
Chad La Joie
lajoie at itumi.biz
Fri Jun 15 15:27:54 BST 2012
Well the standard says that <SingleLogoutService> is "Zero or more
elements of type EndpointType that describe endpoints that support the
Single Logout profiles defined in [SAMLProf]." So, you either do that
particular profile or you don't.
That said, after having turned this over in my head now for years, I
think the only workable solution is going to be defining a new logout
profile that does something like what you're talking about. As far as
I can tell, apps are never going to properly support back-channel
logout and front-channel is just never going to work consistently.
On Fri, Jun 15, 2012 at 10:22 AM, Steven Carmody
<steven_carmody at brown.edu> wrote:
> This implementation clearly is NOT the full Logout of all SPs. But, the
> thinking is that it does provide some value.
>
> So, reading Scott's thoughts at the top of this note -- would this be a
> different profile? Or is this approach "close enough" to the original
> intent that the standard values could be used ?
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
More information about the users
mailing list