SLO
Peter Schober
peter.schober at univie.ac.at
Thu Mar 7 05:45:00 EST 2013
* Rastko Isajev <risajev at calliduscloud.com> [2013-03-07 11:06]:
> As I have found from documentation and from different posts around I have
> found that Single Log Out is not possible yet. Or I am wrong ? If it is
> going like this what is the solution to accomplish this scenario. I saw
> some guys are suggesting closure of browser but that is not OK for me.
Did you read this, specificaly?
https://wiki.shibboleth.net/confluence/display/SHIB2/SLOIssues
Hardly any SP integrates with SAML so that SLO would work reliably.
We can't change that. But maybe you can change it for all deployed SPs
your IDP is federating with. (I doubt it because at one point you'll
add an SP that doesn't support it, say, a large outsourced service "in
the cloud" and then what? "Don't use that service, it doesn't provide
proper SAML2 SLO support" usually does not convince management to
abstain from a service needed for whatever business reasons.)
But if you manage to do that, well yes, having an IdP that supports
SLO would be good. The Shib IDP isn't one of those, at this point.
Deployed SPs are real. Millions of people worldwide are accessing
SAML-protected resources every day. And SLO does not exist there.
So what does the fact that you don't find closing the browser "OK"
mean in this situation?
-peter
More information about the users
mailing list