SLO

JF jamesforrest56 at gmail.com
Wed Jun 12 02:49:27 EDT 2013


Thanks Scott,

we do have complete control over the app but I'll follow your suggestion as I suspect this isn't the only time this will come up.  I'll report back here how we get on.


jf

On 11 Jun 2013, at 22:39, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>> I believe an option for achieving this is:
>> 
>> 1)	On logout having the user access the
>> https://aaa.bbb.com/Shibboleth.sso/Logout to terminate the users session
>> on the SP
>> 2)	Modifying localLogout.html on the SP to redirect the user to the
>> localLogout on the IdP
> 
> You could, but it would probably be "better" in general to use the SAML protocol for that, if for no other reason than if it doesn't work for this constrained a case, it's not even worth continuing to talk about it.
> 
> The local hook is not meant for use by systems that are not tightly coupled, though it sounds like that might be true in this case. To be more explicit, if you don't have direct control over or at least a tight relationship with the systems generating links to the proprietary hook, you're asking for trouble using it, just like any non-standard mechanism.
> 
> -- Scott
> 
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list