IdPv3 SLO redirect request failures

Nate Klingenstein nate.klingenstein at utah.edu
Wed Mar 9 12:42:02 EST 2016


Josh,

We can’t see the full contents of your example because of the ellipsis, but you can literally decode it yourself:

https://rnd.feide.no/software/saml_2_0_debugger/

The /idp/profile/Logout page pretty much just clears your session with the IdP if you land on it.  It’s not formal SAML in any way.  The SLO endpoint is formal SAML.  I don’t know the v3 SLO documentation well yet, but this covers the same concepts in the first few paragraphs:

https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableSLO

Signature issues would be a very good place to start looking.  Unless something is obvious to someone else, the complete query string will be needed for us to see any more.

Take care,
Nate.

{IDP-HOST}/idp/profile/SAML2/Redirect/SLO?SAMLRequest=jVPRcqIwFP0VhteOBlBAMsoMrVLp2tqK2q4vnZAESYXEktCqX7%2Bg66x92E5fT8655557b%2FoSFfkWTsRa%3D…
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160309/0ff021f1/attachment.html>


More information about the users mailing list