IdPv3 SLO redirect request failures

O'Dowd, Josh Josh.O'Dowd at mso.umt.edu
Wed Mar 9 12:32:48 EST 2016


Good Morning,

We have been having some issues with some of our third-party cloud vendors, concerning SLO redirected logout requests.  They are coming into our IdP with request URLs that look like the following example:
{IDP-HOST}/idp/profile/SAML2/Redirect/SLO?SAMLRequest=jVPRcqIwFP0VhteOBlBAMsoMrVLp2tqK2q4vnZAESYXEktCqX7%2Bg66x92E5fT8655557b%2FoSFfkWTsRa%3D...

These requests end up landing the user on an IdP error view with the OOB response basically saying that the application isn't configured properly.

The workaround that seems to be popular is for the SP to change to a local logout with a URL redirect to our ../idp/profile/Logout page.  This works for our purposes, but recently is not an option for one of our 3rdP SPs.  I would very much like to understand what is causing the issue.  I have a suspicion that is something to do with the SAMLRequest parameter, which looks like maybe it is signed?  If that is in fact the case, is there a config on our IdP that needs to be changed to handle these?  If not, I would appreciate any thoughts...

As always, thanks for your time.

Josh O'Dowd
Software Systems Engineer
Central IT, University of Montana
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160309/bfbb147b/attachment.html>


More information about the users mailing list