Genetec SingleLogoutService?
Scott Gilbert
sgilbert at ucsb.edu
Fri Jul 8 22:11:31 UTC 2022
IdP 3.4.6
Hi- I am trying to set up SSO with genetec and they say I must have
SingleLogoutService in my metadata. We do not have that explicitly stated
in our IdP metadata, we never have. See below. This company uses third
party authentication services and does not play well with generic SAML 2.0
so it is difficult to troubleshoot.
"The url you connect to the webclient isn’t reflective of the uri we
present. The construction of the saml request is done at the Directory
server level, and the user gets redirected through our own proxy.
Definitely the redirect uri’s are correct. Right now the failure is
happening at our software, when we proxy the request. This indicates that a
requirement hasn’t been filled.
In this case the software is expecting for there to be a
SingleLogoutService binding to be available in the metadata. Below is an
example from an okta saml config I’ve used in the pas
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="
https://dev-47053337.okta.com/app/dev-47053337_securitycenterokta_1/exk29ooutn7iuBXBu5d7/slo/saml
"/>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="
https://dev-47053337.okta.com/app/dev-47053337_securitycenterokta_1/exk29ooutn7iuBXBu5d7/slo/saml
"/>"
Scott Gilbert
IAM/Cloud System Administrator
Enterprise Technology Services
University of California Santa Barbara
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220708/3be60eba/attachment.htm>
More information about the users
mailing list