SLO logging in idp-process.log
Peter Schober
peter.schober at univie.ac.at
Mon Nov 25 06:05:36 EST 2013
* Gene Matthews <gmatthew at hitachi-cta.com> [2013-11-25 06:52]:
> Currently, I can go to the SP site, get redirected back to my idp,
> authenticate, and get redirected back to SP, logged in. The SP has a
> logout button that they tell me is calling the
> /SAML2/Redirect/SLO. When tailing the idp-process.log while clicking
> their logout button however, I don't see anything in the log, and
> all it seems to to is log me back in to their portal. I say 'log me
> back in' although I don't acutally see any activity in the
> idp-process.log when this is happening. The SP's portal is, after
> the SSO authentication, relaying out to their application on a
> remote CPE device tied to the username used for authentication. Whne
> I click the SP logout, I see a page briefly displayed saying i'm
> being 'redcirected to device', but nothing in idp log. Which would
> lead me to believe they are not actually calling the SLO process at
> the idp.
Given that this ("Redirect") is a front channel request you'd clearly
see any of this in your web browser, e.g. using Firefox and the HTTP
Live Headers or SAMLtracer extension.
-peter
More information about the users
mailing list