IDP Logout, text asking user whether or not to kill the IDP session
Steven Carmody
steven_carmody at brown.edu
Wed Oct 16 16:58:10 EDT 2013
On 10/16/13 1:43 PM, Cantor, Scott wrote:
> On 10/16/13 1:12 PM, "Steven Carmody"<steven_carmody at brown.edu> wrote:
>>
>> And a Shibboleth question for the list -- I believe the Logout endpoint
>> in the Shib SP can be passed a url; after killing the local SP session
>> it will redirect the browser to that url. Typically, that URL would be
>> the Logout endpoint of the IDP that was used ....
>
> If you do the proprietary thing, yes. The SAML logout case just goes to
> the endpoint in the metadata.
>
thanks.
is it possible to redirect to the SP's /Shibboleth.sso/Logout endpoint,
and tell it "and redirect to the metadata-based Logout endpoint of
whatever IDP was used to create this session?"
As I understand it, I can pass the Logout endpoint a url to redirect to,
but my application would have to identify the IDP that was used, and
then "somehow" obtain the url for its Logout endpoint.
is there a simpler way ?
thanks!
More information about the users
mailing list