SP logout produces IdP error
Cantor, Scott
cantor.2 at osu.edu
Tue Sep 19 17:59:52 EDT 2017
> Could someone provide clarification on whether this is a problem that I
> should correct on my IdP (at risk of breaking existing setups) or if I should
> continue to focus on the SP side?
That is not answerable. What is factual is that, if the problem is in fact the same, then the key in the metadata does not correspond to the decryption key you are running the IdP with. Which one is right and which one is wrong is not an objective question from the outside of the system.
There is no possible way that any other SP running with the same metadata would work if they encrypted the ID but since most of them probably aren't encrypting there's not necessarily anything interesting about the fact that they are. Or they're not even doing SAML logout at all perhaps, as most in fact don't.
And if there's different metadata given to different SPs with different public keys in it, then all bets are off and any change could have ripple effects. The IdP can decrypt with any number of keys it's told to use, so it's always possible to make it work if there were a need to temporarily allow for a key but then get rid of it later, but I can't tell you what keys are real or fake or missing or whatever.
-- Scott
More information about the users
mailing list