Question related to "Local Logout" provided by Shibboleth IdP 2.4.0

Cantor, Scott cantor.2 at osu.edu
Mon Sep 2 12:54:47 EDT 2013


On 9/2/13 3:30 AM, "Jan Keirse" <jan.keirse at tvh.be> wrote:
>
>Would it be a feasible option to serve a page to the end user after
>logout.jsp that contains iframes for each service provider's logout
>page?

That is the only option, but it requires SPs *and* applications be able to
execute logout without access to the session cookie. I can eventually make
the SP do that, but there are almost no apps that will ever be able to do
that.

>That may require an extention to the protocol to let the service
>provider provide it's logout url to the IDP.

SAML already has that.

-- Scott




More information about the users mailing list