Unable to achieve Web SSO logout
B Da Bahia
bidabahia at gmail.com
Thu Aug 14 04:17:01 EDT 2014
Thank you Randy, that makes a lot of sense!
Nevertheless, after enabling FBA and disabling Windows Authentication in
the IdP IIS (and the SP IIS) I've broken the SSO and don't get the IdP
login form anymore, but instead this error message:
opensaml::FatalProfileException at (https://mySP/Shibboleth.sso/SAML2/POST)
SAML response reported an IdP error.
Error from identity provider:
*Status:* urn:oasis:names:tc:SAML:2.0:status:Responder
I've tried to troubleshoot it but nothing really alarming seems to popup
from the logs.
The app proxy shows a 500 Server error on the following request:
POST https://mySP/Shibboleth.sso/SAML2/POST
Thank you once again
Bida
On Wed, Aug 13, 2014 at 7:17 PM, Randy Wiemer <wiemerr at hotmail.com> wrote:
> You need to configure ADFS to use forms-based authentication in order to
> achieve SLO. Windows integrated will use Kerberos or NTLM with IE where
> there is no real concept of logoff short of logging off the computer. With
> both of those protocols the goal is to use the desktop credentials to
> seamlessly access web sites.
>
> Randy
>
>
> *From:* B Da Bahia <bidabahia at gmail.com>
> *Sent:* Wednesday, August 13, 2014 11:49 AM
> *To:* Shib Users <users at shibboleth.net>
>
> Hello list,
>
> Newbie here. I'm attempting to setup a simple SAML 2.0 federation with:
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140814/1a1175b3/attachment.html
More information about the users
mailing list