Logout SAML Error message v3

David Langenberg davel at uchicago.edu
Sat Jan 17 14:15:34 EST 2015


Ok, well in that case can I ask that the idp (or how to configure the IdP )
to instead perform the logout but not return to the sp if it's configured
for client side sessions?  Perhaps just terminate on the local logout page?

Dave

On Saturday, January 17, 2015, Cantor, Scott <cantor.2 at osu.edu> wrote:

> Your "bug" is that you're trying to use client-side session storage with
> logout, which is impossible at present. That only changes if we manage to
> hack something together with DOM storage as a back-end, cookies will never
> work. Setting the other properties doesn’t affect storage implementations
> that don't support them.
>
> > It's also saying this:
> >
> > 2015-01-16 22:15:30,519 - DEBUG
> > [net.shibboleth.idp.saml.profile.impl.ExtractSubjectFromRequest:144] -
> > Profile Action ExtractSubjectFromRequest: No Subject NameID or
> > NameIdentifier in message
>
> That's an unfortunate message that doesn't matter for logout requests, the
> subject doesn't get "decoded" on logouts, the NameID just gets used
> directly.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net <javascript:;>



-- 
David Langenberg
Identity & Access Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150117/fd61dadf/attachment.html 


More information about the users mailing list