SP Logout

Peter Schober peter.schober at univie.ac.at
Tue Sep 11 12:25:00 EDT 2012


* Cantor, Scott <cantor.2 at osu.edu> [2012-09-11 18:07]:
> There are several bugs that are really more like design incompatibilities
> between SAML logout and the application concept. The latter predates
> logout, and it doesn't really work that well with it. There's an open bug
> on at least one of the issues related to not getting a second
> application's session terminated when the first one is logged out. The IdP
> might know about the extra session(s), but it doesn't know which SLO
> endpoint to send a request to. And the back channel doesn't fix that
> either, so my suggestion was probably wrong.

With seperate applications, each with its own EntityDescriptor and SLO
endpoint in metadata, how would that still fail (assuming the IdP had
working support for SLO, of course)?
-peter


More information about the users mailing list