IdPv3 SLO redirect request failures

Cantor, Scott cantor.2 at osu.edu
Wed Mar 9 13:03:47 EST 2016


On 3/9/16, 12:57 PM, "users on behalf of Nate Klingenstein" <users-bounces at shibboleth.net on behalf of ndk at sudonym.me> wrote:



>I would track down Scott’s suggestion about metadata, but there’s at least one interesting thing in the encoded message: they appear to be using the asynchronous logout extension, and I don’t know if that’s implemented here or not.

It is. That pretty much means the SP is using Shibboleth, so they just didn't provide accurate metadata. That speaks to deeper problems with more serious implications than logout not working.

>Rule, not the exception, I’m afraid, but a lot of this has to do with the inherent nature of logout on the web.  I’ve never pushed for SAML 2 SLO protocol support because it immediately leads into a whole lot of logout orchestration questions.  The /idp/profile/Logout
> handler is way more predictable.

Both of them lead to mostly the same questions and problems.

-- Scott



More information about the users mailing list