make SP to not validate logout responses

ignasr at vault13.lt ignasr at vault13.lt
Tue Oct 16 03:53:26 EDT 2012


Hello all,

is it possible to make Shibboleth 2.5.0 SP not require logout responses 
to be signed?

IdP is SimpleSAMLphp, and I get errors:

***
opensaml::SecurityPolicyException at 
(https://my.domain/Shibboleth.sso/SLO/Redirect)
Security of LogoutResponse not established.
***

wiki didn't help. I have found lots of threads talking about problems 
with SLO, but haven't succeeded if finding one with a specific 
configuration option to turn validation off.

If there isn't one, what's the best way to hide this error from users?

Thank you,
IgnasR


More information about the users mailing list