Shibboleth SP logout issue

Cantor, Scott cantor.2 at osu.edu
Thu Oct 13 13:33:44 EDT 2016


> If the <Location '/Shibboleth.sso'> block is missing "Satisfy Any" and "Allow
> from all", apache logs / displays:
> [Thu Oct 13 13:14:19 2016] [error] [client xxx.xxx.xxx.xxx] None of the
> configured LogoutInitiators handled the request.

That's what doesn't make any sense.

> If the location block is configured correctly (based on
> /etc/shibboleth/apache22.config), it proceeds.  I'm still getting a error (a
> certificate disagreement), but at least it's talking to the IDP.

"Correctly" should not require those settings, I added them because people said they needed them despite seeing no way that could be true, but more to the point, it should not cause that behavior. Deny the request outright, sure, that's what authorization should do. It doesn't make sense. If you could file a bug, just a link to the thread is fine, at least I can try and reproduce it at some point.

-- Scott



More information about the users mailing list