Message Security Error

Cantor, Scott cantor.2 at osu.edu
Mon Feb 26 16:58:01 EST 2018


> I found the log message. I missed it because it was a warning instead of an
> error. Sorry about that.

We tend to reserve "error" for something actually wrong with the system and "warn" for runtime conditions that are potentially concerning but ultimately either specific to another malfunctioning system or are unavoidable.

> We don't support the back-channel (though it's possible that we are
> accidentally advertising that we do). Would lack of back-channel support be
> something that could cause this error?

No, if the error is what I said it was, the error isn't yours. Logout messages are required to be signed. If you want to turn that off you can, there's a property for it. That is not SAML-compliant, so it's not the default.

-- Scott



More information about the users mailing list