One good reason??

Cantor, Scott cantor.2 at osu.edu
Mon Dec 18 15:37:10 EST 2017


> I am just wondering if anyone has one valid excuse why a vendor that
> "supports" SAML2 authentication, would not honor IdP logout, either by
> SingleLogoutRequest or redirect to the Logout handler URL?

Usually it's a sign their SSO support is only very minimally integrated into the application.

> I think I should be in my rights to expect that as an SSO IdP admin.  Maybe
> I'm too needy.

I guess on the list of things I expect, that's low on the list under automated key revocation.

It's a legitimate complaint that we ignored PKIX I suppose, but since the vendors all do/did also for the most part, their lack of a story on revocation is fairly indefensible.

-- Scott



More information about the users mailing list