Logout SAML Error message v3
David Langenberg
davel at uchicago.edu
Tue Jan 20 14:38:35 EST 2015
On Tue, Jan 20, 2015 at 7:37 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> > Ok, so the v3 IdP, by default, is set to use client-side sessions, the
> auto-
> > generated metadata has the logout endpoints advertised, and the docs
> > currently written seem to encourage the deployer to stick with
> client-side
> > sessions.
>
> Defaults are just defaults. People need to use what they think they need
> to use. There's no discussion on logout yet because it's not really
> implemented more than before, so the impact on settings isn't really
> documented to this point.
>
> > I would very much appreciate it if the IdP would do something
> > more in this case than sending the SP the generic message of "An error
> has
> > occurred." Ideally, the IdP would either kill the session cookies in the
> > browser and display some kind of "you only think you've SLO'd" message or
> > something a little more detailed would show up in the process log / be
> sent
> > to the SP describing "client-side sessions are not compatible with
> logout".
>
> That will be a fair bit of work, so you'd best file a bug to track it.
>
IDP-576 created for those following along at home who want to watch it.
> > I am interested though in the specific event to trap in the meantime.
>
> Once I have time to research what actually gets triggered, I can put that
> into the issue filed.
>
Sounds good, thanks for the help.
Dave
--
David Langenberg
Identity & Access Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150120/ca8c8579/attachment.html
More information about the users
mailing list