Use of EncryptedID not supported in LogoutRequest

Lipscomb, Gary glipscomb at csu.edu.au
Wed Jul 13 20:47:48 EDT 2016


Hi Scott,

Signing is still on, as well as encryption. When encryption was turned off at the SP got the following

    <ApplicationDefaults entityID="https://scciprod01.csumain.csu.edu.au/shibboleth-sp"
                         REMOTE_USER="uid eppn"
                         signing="true",encryption="false">


opensaml::FatalProfileException

.........

opensaml:: FatalProfileException at (https://AAAA.BBBB.csu.edu.au/Shibboleth.sso/SLO/Redirect)
SAML response reported an IdP error

Error from identity provider:

Status: urn:oasis:names:tc:SAML:2.0:status:Responser
Sub-Status: urn:oasis:names:tc:SAML:2.0:status:RequestDenied
Message: Message did not meet security requirements


Regards

Gary


> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor,
> Scott
> Sent: Thursday, 14 July 2016 10:31
> To: Shib Users <users at shibboleth.net>
> Subject: Re: Use of EncryptedID not supported in LogoutRequest
>
> On 7/13/16, 8:23 PM, "users on behalf of Cantor, Scott" <users-
> bounces at shibboleth.net on behalf of cantor.2 at osu.edu> wrote:
>
>     On 7/13/16, 8:09 PM, "users on behalf of Lipscomb, Gary" <users-
> bounces at shibboleth.net on behalf of glipscomb at csu.edu.au> wrote:
>
>     >    Log [1] shown below when attempting logout  as well as metadata [2] at
> idp
>
> >    That is not the log of the attempt that led to the error you asked
> > about. It's a log of a failed logout request due to a lack of a
> > signature. That is unrelated and not caused by anything you have asked
> about to this point.
>
> Unless you were trying to answer my question about what broke when you
> turned encryption off, in which case you are confused about signing and
> encryption. Turning encryption off is not turning signing off, or vice versa,
> and I never told you to turn off signing. It will break, which it did, so I imagine
> that's what you did.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-
> unsubscribe at shibboleth.net

Charles Sturt University

| ALBURY-WODONGA | BATHURST | CANBERRA | DUBBO | GOULBURN | MELBOURNE | ORANGE | PORT MACQUARIE | SYDNEY | WAGGA WAGGA |

LEGAL NOTICE
This email (and any attachment) is confidential and is intended for the use of the addressee(s) only. If you are not the intended recipient of this email, you must not copy, distribute, take any action in reliance on it or disclose it to anyone. Any confidentiality is not waived or lost by reason of mistaken delivery. Email should be checked for viruses and defects before opening. Charles Sturt University (CSU) does not accept liability for viruses or any consequence which arise as a result of this email transmission. Email communications with CSU may be subject to automated email filtering, which could result in the delay or deletion of a legitimate email before it is read at CSU. The views expressed in this email are not necessarily those of CSU.

Charles Sturt University in Australia
http://www.csu.edu.au
The Grange Chancellery, Panorama Avenue, Bathurst NSW Australia 2795
(ABN: 83 878 708 551; CRICOS Provider Numbers: 00005F (NSW), 01947G (VIC), 02960B (ACT)). TEQSA Provider Number: PV12018


Consider the environment before printing this email.


More information about the users mailing list