AD FS IdP Error while logging out from IdP
Boyd, Todd M.
tmboyd1 at ccis.edu
Fri Jan 25 11:51:46 EST 2019
If you want to troubleshoot that error, you need to look up what actually happened in the ADFS logs that are associated with that activity ID. I believe you have to enable Trace Debugging and then use the ADFS PowerShell cmdlets to pull the log.
https://www.jaapbrasser.com/troubleshooting-adfs-enabling-additional-logging/
-Todd
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of raghu.avula at ucf.edu
Sent: Friday, January 25, 2019 10:37 AM
To: users at shibboleth.net
Subject: AD FS IdP Error while logging out from IdP
Hello All,
We are facing a logout issue while logging out from AD FS IdP Session.
SP: Shibboleth
IdP: Microsoft AD FS
*SP Metadata*:
<md:ArtifactResolutionService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
Location="https://sp.website.com/Shibboleth.sso/Artifact/SOAP" index="1"/>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
Location="https://sp.website.com/Shibboleth.sso/SLO/SOAP"/>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
Location="https://sp.website.com/Shibboleth.sso/SLO/Redirect"/>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Location="https://sp.website.com/Shibboleth.sso/SLO/POST"/>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"
Location="https://sp.website.com/Shibboleth.sso/SLO/Artifact"/>
<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Location="https://sp.website.com/Shibboleth.sso/SAML2/POST" index="1"/>
<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"
Location="https://sp.website.com/Shibboleth.sso/SAML2/POST-SimpleSign"
index="2"/>
<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"
Location="https://sp.website.com/Shibboleth.sso/SAML2/Artifact" index="3"/>
<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS"
Location="https://sp.website.com/Shibboleth.sso/SAML2/ECP" index="4"/>
<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
Location="https://sp.website.com/Shibboleth.sso/SAML/POST" index="5"/>
<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
Location="https://sp.website.com/Shibboleth.sso/SAML/Artifact" index="6"/>
*AD FS SAML Logout Endpoints: *
SAML Assertion Consumer Endpoints
https://sp.website.com/Shibboleth.sso/SAML2/POST
https://sp.website.com/Shibboleth.sso/SAML2/Articraft
SAML Logout Endpoints:
https://federation.xxx.xxx/adfs/ls/?wa=wsignout1.0
*Redirection from SP to IdP while logout*:
https://sp.website.com/Shibboleth.sso/Logout?return=https://federation.xxx.xxx/adfs/ls/?wa=wsignout1.0
*Error while logging out from Application*:
An error occurred
An error occurred. Contact your administrator for more information.
Error details
Activity ID: 00000000-0000-0000-8e8e-0080010000ba
Error time: Fri, 25 Jan 2019 16:16:01 GMT
Cookie: enabled
User agent string: Mozilla/5.0 (Windows NT 6.1; Win64; x64)
AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36
Application session and SP session are invalidated but not the IdP session.
Let me know if you need any more information.
--
Sent from: http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list