Error 404 after processing LogoutResponse from IdP on SP

Robert Ayrapetyan robert.ayrapetyan at gmail.com
Mon Jul 21 20:41:35 EDT 2014


In browser traces 404 page is returned "from" the same page, from which
"Security of LogoutResponse not established." is being returned.
Please see links below: these are traces for signed and non-signed
LogoutResponse. How is that possible?


http://postimg.org/image/quxyysa65/ - LogoutResponse signed, error 404
http://postimg.org/image/tt27925nf/ - LogoutResponse NOT signed, error 500


On 07/21/14 17:30, Robert Ayrapetyan wrote:


> On 07/21/14 16:47, Cantor, Scott wrote:
>> On 7/21/14, 7:41 PM, "Robert Ayrapetyan" <robert.ayrapetyan at gmail.com>
>> wrote:
>>
>>> Trying to figure out why Shibboleth SP returns 404 (page not found)
>>> error instead of redirecting to "return" URL.
>>
>> Trace it and determine what URL is requested that causes a 404.
>>
>>> Just redirect user "somewhere" on step 3, destroying idp cookie, and not
>>> return anything back to SP. This works pretty well, because both SP and
>>> IDP cookies/sessions are destroyed at this moment.
>>
>> It isn't sensible to expect a global logout, impossible though it is, to
>> end at an SP. Doesn't really make any sense from a UI point of view, and
>> it really would never work, since it makes informing the user of the
>> state
>> of things impossible.
>>
>> -- Scott
>>


More information about the users mailing list