Unable to achieve Web SSO logout

B Da Bahia bidabahia at gmail.com
Thu Aug 14 04:17:01 EDT 2014


Thank you Randy, that makes a lot of sense!

Nevertheless, after enabling FBA and disabling Windows Authentication in
the IdP IIS (and the SP IIS) I've broken the SSO and don't get the IdP
login form anymore, but instead this error message:

opensaml::FatalProfileException at (https://mySP/Shibboleth.sso/SAML2/POST)

SAML response reported an IdP error.

Error from identity provider:

*Status:* urn:oasis:names:tc:SAML:2.0:status:Responder

I've tried to troubleshoot it but nothing really alarming seems to popup
from the logs.

The app proxy shows a 500 Server error on the following request:

POST   https://mySP/Shibboleth.sso/SAML2/POST

Thank you once again

Bida


On Wed, Aug 13, 2014 at 7:17 PM, Randy Wiemer <wiemerr at hotmail.com> wrote:

>  You need to configure ADFS to use forms-based authentication in order to
> achieve SLO.  Windows integrated will use Kerberos or NTLM with IE where
> there is no real concept of logoff short of logging off the computer.  With
> both of those protocols the goal is to use the desktop credentials to
> seamlessly access web sites.
>
> Randy
>
>
> *From:* B Da Bahia <bidabahia at gmail.com>
> *Sent:* ‎Wednesday‎, ‎August‎ ‎13‎, ‎2014 ‎11‎:‎49‎ ‎AM
> *To:* Shib Users <users at shibboleth.net>
>
> Hello list,
>
> Newbie here. I'm attempting to setup a simple SAML 2.0 federation  with:
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140814/1a1175b3/attachment.html 


More information about the users mailing list