IDP Logout, text asking user whether or not to kill the IDP session

Steven Carmody steven_carmody at brown.edu
Wed Oct 16 16:58:10 EDT 2013


On 10/16/13 1:43 PM, Cantor, Scott wrote:
> On 10/16/13 1:12 PM, "Steven Carmody"<steven_carmody at brown.edu>  wrote:
>>
>> And a Shibboleth question for the list -- I believe the Logout endpoint
>> in the Shib SP can be passed a url; after killing the local SP session
>> it will redirect the browser to that url. Typically, that URL would be
>> the Logout endpoint of the IDP that was used ....
>
> If you do the proprietary thing, yes. The SAML logout case just goes to
> the endpoint in the metadata.
>

thanks.

is it possible to redirect to the SP's /Shibboleth.sso/Logout endpoint, 
and tell it "and redirect to the metadata-based Logout endpoint of 
whatever IDP was used to create this session?"

As I understand it, I can pass the Logout endpoint a url to redirect to, 
but my application would have to identify the IDP that was used, and 
then "somehow" obtain the url for its Logout endpoint.

is there a simpler way ?

thanks!


More information about the users mailing list