Zoom Integration with Shibboleth IdP v3 and non-signed logout request

Scott Koranda skoranda at gmail.com
Thu Apr 16 16:37:53 EDT 2015


On Thu, Apr 16, 2015 at 1:59 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 4/16/15, 2:48 PM, "Scott Koranda" <skoranda at gmail.com> wrote:
>>
>>The Zoom UI presents a "SIGN OUT" link. Clicking that causes the
>>browser to visit the IdP v3 SLO endpoint
>>/idp/profile/SAML2/Redirect/SLO (that is the URL endpoint I configured
>>Zoom to use). The SAML sent with the redirect is an unsigned
>><LogoutRequest>.
>
> We haven't spent time documenting override of the default security rules on request handling, but obviously that's something we can outline if you need it. It's more hidden in V3 for obvious reasons.
>

It appears that I will want to understand how to turn off the
requirement that the <LogoutRequest> be signed (per replying party if
possible). If you can outline what is necessary I would be grateful.

I would still like to hear how other integrators are handling "SIGN
OUT" for Zoom.

I did learn that in the control panel if the URL for "logout" for the
IdP is left blank then Zoom will simply end its session and not take
any other action.

Thanks,

Scott K


More information about the users mailing list