SLO question

Ulrich Leodolter ulrich.leodolter at obvsg.at
Mon Jul 14 02:10:21 EDT 2014


hello, 

for testing and internal use i have installed shibboleth IdP 2.4.0.
so far everything works and i can login from existing SP 2.5.2.

then i was interested in testing the SLO as described at
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableSLO
login/logout from single SP1 works fine, no wonder :)
then i tried to login (single browser) from SP1 and SP2 to my
testing IdP.  after login to both the first logout from SP1
results in  *Partital Logout*, that seems reasonable.

but the second logout from SP2 results in:
---
opensaml::FatalProfileException at
(https://sp2.my.domain/Shibboleth.sso/SLO/Redirect)

SAML response reported an IdP error.

Error from identity provider:

        Status: urn:oasis:names:tc:SAML:2.0:status:Requester
        Sub-Status: urn:oasis:names:tc:SAML:2.0:status:UnknownPrincipal
---

the information provided seems reasonable too,  but i am unsure
if i have configured everything ok.

just like to get a confirmation that this behavior is what i can
expect from current implementation.

thanks
ulrich




More information about the users mailing list