IdPv3 SLO redirect request failures

O'Dowd, Josh Josh.O'Dowd at mso.umt.edu
Wed Mar 9 12:46:53 EST 2016


Thanks Nate,

The complete query string is:

SAMLRequest=jVPRcqIwFP0VhteOBlBAMsoMrVLp2tqK2q4vnZAESYXEktCqX7%2Bg66x92E5fT8655557b%2FoSFfkWTsRaVGpG3ysqlbYrci7h8WWgVyWHAkkmIUcFlVBhGAf3E2i1DbgthRJY5Lo2rHWMI8UEH%2BiZUlsJAcjFmvF2Vag2JRVgZAtqQcpyCpoKFphRwkqKFYgnU12LhgP9lWC367ou9jpez8BJYiddu4cd0%2B4gRLvUq2lSVjTiUiGuBrplmE7L6LQMb2660LSh5ax0bUlLeeykblL3%2B00SeNSVF9m%2Bj4akpGUTR%2FfPcWrgg2EqDbON5AaRgsnGRbY5VUBmLElETlUG5LYPLixP%2Fls42inKjwK%2Fj2QuYCD3HGel4KKSf%2Ftq8J%2BNHNKdqul1hVat0YF%2F8vxq0yAWfKiLRMOL5NZPo2uhKAukvqc3CCOt9EiFqkS1O%2BVK1xrfpwrlLGW0%2FO4q%2Fs1O1%2BLH%2F8h%2BPn3dDwJyWD0%2F7FcvTzt5MCeBE0YzS4x6YH97exDAeslImE1%2Fydj%2B2FXY%2Bx2%2BLSI0vgPXIxIlZiqK25url8l8tHSWN%2FQ92XiPCDB7uaFRGK3SAi9Csp9OV7lroL2d3i%2Bun3Axc0dzcXU%2FnvJNsGQOcQ93SfC4XqzRHY7HqTVzsv3bc3dOkt4nHV6P43k45g%2FdZTAYnHZ33tT5YGJ6TBhxQnf%2Bq2tbnovttGtZVoI7PWQ69X%2FoIZQQ17GJc97%2FF9UZ%2FPK%2F%2FT8%3D&RelayState=ss%3Amem%3Aafed0010b972f34e5176afceb3f3a2b35bf104556330a2adeada73172508f5ae&SigAlg=http%3A%2F%2Fwww.w3.org%2F2000%2F09%2Fxmldsig%23rsa-sha1&Signature=pd4PeGOt6x6v5zXTsUC5mi55vl99bE7WnFLbdoFjD7YzuTPmGmNCsY8Ng8Kk41m8iT0I6vl9vdGyRx1CVSHnaVhjqsBgUgUSVw1u%2FxPSIhpfJEsJb1YP4qDJDSP7va7%2FynjUuD1m%2Fo6JcroB11M3CD8cumAW4eAOCcdU2XcxsWQIwUPC4eg0EkZB4HFZl0ZWTN1lgfWZKkvEp9C8ri6UTVix31XvTyci7jnRe3nVM7swb137hgac%2BgFKlTxO60x2%2FGPoNtK40FgNA4kMo%2B%2FleXXg3%2BMYOPllMyelLY6WLV8Woy1EIAnNSbcUJqON3Ijw%2FR%2BRTigVIwO3%2Bm%2FppLNneA%3D%3D

I understand that the idp/profile/Logout isn’t really SAML2 logout.  It is amazing to me that there are ‘professional’ cloud services out there that offer SAML2 authentication and have no idea how to configure their SP software for SAML2 logout.  They just say ‘we don’t do that’ and offer to do post-local logout redirect.

Thanks again for your time and assistance.

Josh

From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Nate Klingenstein
Sent: Wednesday, March 9, 2016 10:42 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: IdPv3 SLO redirect request failures

Josh,

We can’t see the full contents of your example because of the ellipsis, but you can literally decode it yourself:

https://rnd.feide.no/software/saml_2_0_debugger/

The /idp/profile/Logout page pretty much just clears your session with the IdP if you land on it.  It’s not formal SAML in any way.  The SLO endpoint is formal SAML.  I don’t know the v3 SLO documentation well yet, but this covers the same concepts in the first few paragraphs:

https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableSLO

Signature issues would be a very good place to start looking.  Unless something is obvious to someone else, the complete query string will be needed for us to see any more.

Take care,
Nate.

{IDP-HOST}/idp/profile/SAML2/Redirect/SLO?SAMLRequest=jVPRcqIwFP0VhteOBlBAMsoMrVLp2tqK2q4vnZAESYXEktCqX7%2Bg66x92E5fT8655557b%2FoSFfkWTsRa%3D…
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160309/fb0353cd/attachment-0001.html>


More information about the users mailing list