Logout Issue "Secondary lookup failed on service ID"

Lukas Hämmerle lukas.haemmerle at switch.ch
Thu Mar 2 03:23:30 EST 2017


Thanks for the helpful inputs. It works now :-)

On 01.03.17 18:31, Cantor, Scott wrote:
> On 3/1/17, 12:06 PM, "users on behalf of Lukas Hämmerle"
> <users-bounces at shibboleth.net on behalf of lukas.haemmerle at switch.ch>
> wrote:
> 
>> However, that secondary key was used in the SAML assertion issued
>> for that SP in the NameID:
> 
> I'd have to review the logging, but a very common bug with SPs is
> sending back the wrong Format in the NameID. I would at least check
> that in the request.

I checked and the SAML NameID looked good. So, no worries there.


> Client storage is fine, but you have to enable HTML local storage,
> you can't do logout if cookies are the medium. That also means some
> clients could fail while others succeed, though most clients now
> support local storage.

It indeed had to to with the storage mechanism. So far we have been
using the default cookie storage. Logout worked as expected once we
switched to persistent DB storage (shibboleth.JPAStorageService)


> I believe the UI needs to change to generally keep things at the IdP
> and get rid of some of the weird cases where it returns to the SP if
> something bad happens, that's not really a good thing for it to be
> inconsistent. We'd still send back the error in the hidden frame, but
> the IdP needs to handle the UI.

Yes, some UI work remains to do on our side.

Best Regards
Lukas


-- 
SWITCH
Lukas Hämmerle, Central Solutions
GÉANT Project Task Leader of
eduGAIN Service Development - Research and Service Providers
Werdstrasse 2, P.O. Box, 8021 Zurich, Switzerland
phone +41 44 268 15 05, direct +41 44 268 15 64
lukas.haemmerle at switch.ch, http://www.switch.ch

30 years of pioneering the Swiss Internet. Celebrate with us at
https://swit.ch/30years



More information about the users mailing list