Logout SAML Error message v3

David Langenberg davel at uchicago.edu
Mon Jan 19 22:55:21 EST 2015


On Sat, Jan 17, 2015 at 12:25 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > Ok, well in that case can I ask that the idp (or how to configure the
> IdP ) to
> > instead perform the logout but not return to the sp if it's configured
> for client
> > side sessions?  Perhaps just terminate on the local logout page?
>
> Is the SP including the Async extension? If so, I may have either been
> unable to get it to stop returning, or there's a bug.
>

No, the SP is not including Async (Shib SP 2.4.3).  So, looks like from the
docs I need to update that SP to 2.5.x and configure it to do so.


>
> If not, that was meant to be the way to ask for that. As a more brute
> force choice, you can override an error event so that it becomes a local
> error, but I'll have to go digging to see what the event is in this case.
>

Ok, so the v3 IdP, by default, is set to use client-side sessions, the
auto-generated metadata has the logout endpoints advertised, and the docs
currently written seem to encourage the deployer to stick with client-side
sessions.  I would very much appreciate it if the IdP would do something
more in this case than sending the SP the generic message of "An error has
occurred."  Ideally, the IdP would either kill the session cookies in the
browser and display some kind of "you only think you've SLO'd" message or
something a little more detailed would show up in the process log / be sent
to the SP describing "client-side sessions are not compatible with logout".

I am interested though in the specific event to trap in the meantime.

Thanks

Dave

-- 
David Langenberg
Identity & Access Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150119/f6aa0451/attachment.html 


More information about the users mailing list