specifying logout endpojnt at the IDP
Cantor, Scott
cantor.2 at osu.edu
Fri Jun 15 16:29:55 BST 2012
On 6/15/12 11:16 AM, "Steven Carmody" <steven_carmody at brown.edu> wrote:
>
>perhaps this is an RFE... asking if the SP could provide a second
>/Logout endpoint... one that would also redirect to the IDP, if it has a
>Logout endpoint ....
It is, it's a new protocol and would have to be documented. Adding it to
metadata properly won't break anything now, but it won't be used either.
It's useful for documentation, which is part of what metadata is.
But it's not "Local" or "SAML2", so the SP is going to ignore it in any
current logout code.
Chad is correct about the very precise wording of the endpoint elements in
the original spec, but I think some of that was tweaked in errata, and it
will get some more adjustment in a next rev to make it clear how to reuse
such elements in appropriate ways.
But whether a non-single logout is really appropriate to put into an
endpoint element called SingleLogoutService is a fair point.
-- Scott
More information about the users
mailing list