SLO
JF
jamesforrest56 at gmail.com
Tue Jun 11 17:22:30 EDT 2013
We have a specific single SP running the Shibboleth SP where we need to implement logout. I have read and reread the sections on the SLO limitations and issues and think I now understand these.
The use case for this is quite straightforward in that the users for this particular service are authenticated by the IdP but will only ever access the single service on a single SP. As such I believe that invalidating the session on the SP and also on the IdP for these users is 'all' that is required.
I believe an option for achieving this is:
1) On logout having the user access the https://aaa.bbb.com/Shibboleth.sso/Logout to terminate the users session on the SP
2) Modifying localLogout.html on the SP to redirect the user to the localLogout on the IdP
Am I on the right lines?
jf
More information about the users
mailing list