IdPv3 SLO redirect request failures
Cantor, Scott
cantor.2 at osu.edu
Wed Mar 9 12:55:03 EST 2016
On 3/9/16, 12:46 PM, "users on behalf of O'Dowd, Josh" <users-bounces at shibboleth.net on behalf of Josh.O'Dowd at mso.umt.edu> wrote:
>I understand that the idp/profile/Logout isn’t really SAML2 logout. It is amazing to me that there are ‘professional’ cloud services out there that offer SAML2 authentication and have no idea how to configure their SP software for SAML2 logout. They just say ‘we don’t do that’ and offer to do post-local logout redirect.
Well, the problem is more that it guarantees a failed logout to everything else. They're willing to initiate logout in a trivial way, but there is no "trivial" *single logout*. That requires the protocol support, and if they don't support requesting a logout with SAML they won't support receiving one either, which makes the entire exercise pointless.
The early feedback I'm getting from our people internally is that if the result of the logout is routinely going to be a red X next to 80% or more of services, it shouldn't be offered, which was my argument for not wasting time on this.
-- Scott
More information about the users
mailing list