SLO logging in idp-process.log
Gene Matthews
gmatthew at hitachi-cta.com
Mon Nov 25 00:51:56 EST 2013
We are experimenting with SLO. I am managing the shibboleth-idp installation. I'm not sure what the SP is running though i don't think it is shibboleth. Assuming I have what I need in my config files on the idp side (might be a large assumption), is it safe to further assume that the SP's calls to my SLO links (they say they are using /SAML2/Redirect/ SLO ) should be logged in idp-process.log??
Currently, I can go to the SP site, get redirected back to my idp, authenticate, and get redirected back to SP, logged in. The SP has a logout button that they tell me is calling the /SAML2/Redirect/SLO. When tailing the idp-process.log while clicking their logout button however, I don't see anything in the log, and all it seems to to is log me back in to their portal. I say 'log me back in' although I don't acutally see any activity in the idp-process.log when this is happening. The SP's portal is, after the SSO authentication, relaying out to their application on a remote CPE device tied to the username used for authentication. Whne I click the SP logout, I see a page briefly displayed saying i'm being 'redcirected to device', but nothing in idp log. Which would lead me to believe they are not actually calling the SLO process at the idp.
Every time I start to think I'm beginning to understand some of this, I realize how clueless I still am <sigh>.
Thanks for any insight!
Gene
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131125/55c353b6/attachment.html
More information about the users
mailing list