idp.encryption.optional and SLO
Cantor, Scott
cantor.2 at osu.edu
Fri Oct 14 21:36:26 EDT 2016
> > Should be (I don't actually see how it could be doing otherwise since it's
> > inheriting from the same code). I'll review the code but you should file a
> bug,
> > I'm in the middle of something else at the moment.
>
> I reviewed and it's definitely taking significant steps to honor that setting but
> the only time this comes up is propagating logout to SPs, which is a very
> poorly tested scenario that requires a lot of strange code internally and
> probably has a bug.
Also, I assume this is with a "native" V3 relying-party.xml config, because I don't believe the optional feature works otherwise with SSO or logout.
-- Scott
More information about the users
mailing list