[EXTERNAL] RE: SLO with SAML question.

Cantor, Scott cantor.2 at osu.edu
Mon Apr 23 12:36:10 EDT 2018


> OK, thanks, that means I’m at least looking at the right thing.  It’s the same
> application, and I know not to point it at the SAML logout endpoint, so the
> question is: what should I point it at?  This is where I’m lost.

The proprietary logout endpoint, I suppose.

> Is there something I need to add to the relying party, for example?

The proprietary logout endpoint doesn't have a protocol or any interaction based on what accesses it, so it's not controlled that way. Nobody has asked to turn it off so there's nothing to configure either way really. The trackSPSessions thing is what allows it to try and propagate but basic IdP logout is automatic and has no configuration other than the view template.

> The vendor’s no help, and if there’s some standard answer to how to direct the logout from
> the application to Shibboleth and cause it to log out of there as well as out of
> the application, I’m not finding it so far (or am finding it and don’t know what
> I’m looking at.)

It's in the page you already read. It's the whole first half of the page.

-- Scott



More information about the users mailing list