IdP not tracking SPs for SSO
Domingues, Michael D
michael-domingues at uiowa.edu
Wed Jan 13 13:48:02 EST 2016
Not sure if it's applicable here as well, but because I ran into this while building out our new IdPs, food for thought:
In addition to the documented idp.config properties which need to be enabled -- along with the process of choosing an appropriate storage mechanism -- the propagating logout functionality David described in his initial message relies upon changes to the view "logout.vm" which were introduced in IdP 3.2.0.
If you've customized this view prior to that release, you'll need to either apply the changes manually to your custom view, or re-create your custom view based on the new logout.vm to enable the described functionality.
Michael Domingues
Directory and Authentication Services, AIS, ITS
University of Iowa
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Wednesday, January 13, 2016 9:43 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: IdP not tracking SPs for SSO
On 1/13/16, 10:37 AM, "users on behalf of David E. Newswanger" <users-bounces at shibboleth.net on behalf of David_Newswanger at berea.edu> wrote:
>
>I suspect the issue might have something to do with not being able to serialize the SP session, but I'm not entirely sure how I would fix that. Thoughts? Do I need to configure the IdP to use a database to track SP sessions?
https://wiki.shibboleth.net/confluence/display/IDP30/StorageConfiguration
See ClientStorageService.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list