idp.encryption.optional and SLO

Cantor, Scott cantor.2 at osu.edu
Fri Oct 14 21:36:26 EDT 2016


> > Should be (I don't actually see how it could be doing otherwise since it's
> > inheriting from the same code). I'll review the code but you should file a
> bug,
> > I'm in the middle of something else at the moment.
> 
> I reviewed and it's definitely taking significant steps to honor that setting but
> the only time this comes up is propagating logout to SPs, which is a very
> poorly tested scenario that requires a lot of strange code internally and
> probably has a bug.

Also, I assume this is with a "native" V3 relying-party.xml config, because I don't believe the optional feature works otherwise with SSO or logout.

-- Scott



More information about the users mailing list