Shibboleth SP logout issue
Cantor, Scott
cantor.2 at osu.edu
Wed Oct 12 15:21:26 EDT 2016
> On Tue, Oct 11, 2016 at 5:45 PM, Cantor, Scott <cantor.2 at osu.edu
> <mailto:cantor.2 at osu.edu> > wrote:
>
> Should the metadata generated by the SP's metagen.sh or the IDP's
> metadata endpoint support SLO?
Generated metadata doesn't matter since it cannot and must not ever be used without curation unless you want a broken deployment. The SP generates whatever metadata reflects its configuration and if logout is enabled, as it is by default, it includes those endpoints. I don't recall what the IdP does but since it's generated only once, it's even less meaningful.
> I turned shibd.log up to DEBUG, and I see the LogoutRequest is generated:
> It doesn't get sent to the browser or the IDP.
I cannot explain that or see how that's possible unless the SP is now just broken and logout no longer works.
> What would cause it to generate the logout request but then not publish it?
Absolutely nothing. If it says it generated the redirect, that's what it should have done. I don't see how anything you posted is physically possible. Assuming I can't trivially reproduce it, then I have no idea how a configuration could be manipulated to fail that way.
-- Scott
More information about the users
mailing list