IdPv3 SLO redirect request failures

Nate Klingenstein ndk at sudonym.me
Wed Mar 9 12:57:01 EST 2016


Josh,

I would track down Scott’s suggestion about metadata, but there’s at least one interesting thing in the encoded message: they appear to be using the asynchronous logout extension, and I don’t know if that’s implemented here or not.  A quick search for “asynchronous” in the IDP30 wiki space reveals nothing relevant to me.

<aslo:Asynchronous xmlns:aslo="urn:oasis:names:tc:SAML:2.0:protocol:ext:async-slo"/>

https://wiki.shibboleth.net/confluence/dosearchsite.action?queryString=asynchronous
http://docs.oasis-open.org/security/saml/Post2.0/saml-async-slo/v1.0/saml-async-slo-v1.0.html

> It is amazing to me that there are ‘professional’ cloud services out there that offer SAML2 authentication and have no idea how to configure their SP software for SAML2 logout.  They just say ‘we don’t do that’ and offer to do post-local logout redirect.

Rule, not the exception, I’m afraid, but a lot of this has to do with the inherent nature of logout on the web.  I’ve never pushed for SAML 2 SLO protocol support because it immediately leads into a whole lot of logout orchestration questions.  The /idp/profile/Logout handler is way more predictable.

Take care,
Nate.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160309/b217d3b5/attachment-0001.html>


More information about the users mailing list