Shibboleth SP logout issue

Liam Hoekenga liamr at umich.edu
Wed Oct 12 14:56:39 EDT 2016


On Tue, Oct 11, 2016 at 5:45 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> In that case the error will be in the other log but the bottom line is the
> metadata's not right.
>

Should the metadata generated by the SP's metagen.sh or the IDP's metadata
endpoint support SLO?

I tried regenerating the SP metadata.
I've tried using the SP metadata from InCommon.
I've fetched a fresh copy of the IDP metadata from the metadata generator.
Everything has SLO endpoints, and everything agrees on each other's
certificates.

I turned shibd.log up to DEBUG, and I see the LogoutRequest is generated:
2016-10-12 12:46:00 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [2]:
marshalled message:
<samlp:LogoutRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
Destination="https://idp-mcomm-qa.dsc.umich.edu/idp/
profile/SAML2/Redirect/SLO" ID="_4659ad8e355e35e2d610232589c3d7d8"
IssueInstant="2016-10-12T16:46:00Z" Version="2.0"><saml:Issuer
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https:/
/shib-sp-test.www.umich.edu/shibboleth</saml:Issuer>
...
</samlp:LogoutRequest>
2016-10-12 12:46:00 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [2]:
signing the message
2016-10-12 12:46:00 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [2]:
message encoded, sending redirect to client

It doesn't get sent to the browser or the IDP.  The SP returns a 500 and
the error message:

shibsp::ConfigurationException at (https://shib-sp-test.www.
umich.edu/Shibboleth.sso/Logout)
None of the configured LogoutInitiators handled the request.


What would cause it to generate the logout request but then not publish it?

Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161012/ace80503/attachment-0001.html>


More information about the users mailing list