SLO

JF jamesforrest56 at gmail.com
Wed Jun 12 15:26:25 EDT 2013


Thanks Scott.
Yes I do mean /Session not /Status….


This is fixable as we have full control over the IdP, SP & App provided the IdP can be configured to supply it.  What I've just realised is that NameID is not what I thought it was - I had simply configured an attribute called 'NameID' and was loading the users login ID into that.

I can't find any sample metadata that shows how this is done but are looking at https://wiki.shibboleth.net/confluence/display/SHIB2/IdPNameIdentifier but am still confused as to how I configure this - apologies but please bare with me a little longer….

The sole use of this is for the logout process - so ideally this should be set to a transient value I think?

Can anyone point me at an example where this is configured?


Thx……


jf





On 12 Jun 2013, at 19:32, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>> The /Status page shows that I have NameID set to the users login name -
> 
> I think you mean /Session, but no, it doesn't. It won't show anything about the NameID, it doesn't know what the assertion's subject contained. The problem is as it said, the IdP is not supplying a NameID in the assertion.
> 
>> does the message mean that I have to have NameID & entityID set as I read
>> it that either will do?
> 
> Both, not neither. But the entityID isn't the problem, that's more of a sanity check. The problem is the NameID isn't supplied.
> 
> If that's not fixable, then you'd have to do with the proprietary option, SAML logout requires a NameID.
> 
> -- Scott
> 
> 
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130612/e302ffc6/attachment.html 


More information about the users mailing list