Synchronous SAML SLO

Peter Schober peter.schober at univie.ac.at
Thu Dec 8 10:28:55 EST 2016


* Martin Haase <Martin.Haase at DAASI.de> [2016-12-08 15:58]:
> I can imagine many SPs that want to terminate their and the IdP's
> session, but cannot speak for other SPs.

That doesn't make any sense, though: Every SP only cares about
itself. But what if I used your SP but didn't use it /last/, i.e., I
initiate logout from another SP?
That's why "logout only at the SP and the IDP, not elsewhere" is
broken by design.

If you really only have one IDP and one SP (and they only know of each
other), why bother with SAML (or SLO, or even externalising
authentication from the application to the IDP) at all?
-peter


More information about the users mailing list