SLO
JF
jamesforrest56 at gmail.com
Wed Jun 12 15:26:25 EDT 2013
Thanks Scott.
Yes I do mean /Session not /Status….
This is fixable as we have full control over the IdP, SP & App provided the IdP can be configured to supply it. What I've just realised is that NameID is not what I thought it was - I had simply configured an attribute called 'NameID' and was loading the users login ID into that.
I can't find any sample metadata that shows how this is done but are looking at https://wiki.shibboleth.net/confluence/display/SHIB2/IdPNameIdentifier but am still confused as to how I configure this - apologies but please bare with me a little longer….
The sole use of this is for the logout process - so ideally this should be set to a transient value I think?
Can anyone point me at an example where this is configured?
Thx……
jf
On 12 Jun 2013, at 19:32, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>> The /Status page shows that I have NameID set to the users login name -
>
> I think you mean /Session, but no, it doesn't. It won't show anything about the NameID, it doesn't know what the assertion's subject contained. The problem is as it said, the IdP is not supplying a NameID in the assertion.
>
>> does the message mean that I have to have NameID & entityID set as I read
>> it that either will do?
>
> Both, not neither. But the entityID isn't the problem, that's more of a sanity check. The problem is the NameID isn't supplied.
>
> If that's not fixable, then you'd have to do with the proprietary option, SAML logout requires a NameID.
>
> -- Scott
>
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130612/e302ffc6/attachment.html
More information about the users
mailing list