Logout fails : No active session(s) found matching LogoutRequest
Lipscomb, Gary
glipscomb at csu.edu.au
Fri Mar 25 04:54:45 UTC 2022
Hi List,
Environment
IdP: 4.1.5
Tomcat: 9.0.55
RHEL: 8.5
We have an SP, “Replicon” which we have configured in their Authentication Provider the
• SLO HTTP Redirect URL with https://idpdev.csu.edu.au/idp/profile/SAML2/Redirect/SLO
Upon logout I’m seeing this error in our idp-process.log
2022-03-25 15:12:31,602 - 10.9.246.156 - INFO [net.shibboleth.idp.saml.saml2.profile.impl.ProcessLogoutRequest:366] - Profile Action ProcessLogoutRequest: No active session(s) found matching LogoutRequest
2022-03-25 15:12:31,603 - 10.9.246.156 - WARN [org.opensaml.profile.action.impl.LogEvent:101] - A non-proceed event occurred while processing the request: SessionNotFound
2022-03-25 15:12:31,616 - 10.9.246.156 - INFO [Shibboleth-Audit.Logout:283] - 10.9.246.156|2022-03-25T04:12:31.589834Z|2022-03-25T04:12:31.616289Z||https://global.replicon.com/!/saml2/REDACTED||||||||true||Redirect|Redirect||Requester|urn:oasis:names:tc:SAML:2.0:status:UnknownPrincipal||Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:98.0) Gecko/20100101 Firefox/98.0
In the logout request the NameID is
• <saml:NameID xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">User1</saml:NameID>
The nameID we send to them in the Response to the AuthnRequest is
• <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier=https://idpdev.csu.edu.au/idp/shibboleth SPNameQualifier=https://global.replicon.com/!/saml2/REDACTED>User1</saml2:NameID>
The have suggested we change the SLO HTTP Redirect URL value to
• https://idpdev.csu.edu.au/idp/profile/Logout?return=https://idpdev.csu.edu.au/idp/profile/Logout based on details found from this link http://antispam.csu.edu.au:32224/?dmVyPTEuMDAxJiYyNTAwZmFlNjY4MzJkMzE4Mj02MjNEMTFEQl8zNjc2M18xODYyXzEmJjI4ZTNjMDEzOGY5NGUzNz0xMzMzJiZ1cmw9aHR0cHMlM0ElMkYlMkZkb2NzJTJFc2hpYiUyRW5jc3UlMkVlZHUlMkZkb2NzJTJGbG9nb3V0JTJFaHRtbA==. This does work.
Looking further based on information obtained here https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631719/LogoutConfiguration I’ve modified the URL to just
• https://idpdev.csu.edu.au/idp/profile/Logout
This works as well. Is it the best way?
Replicon support are saying there is nothing wrong with their Logout Request[1]
Trying to get them to send the NameID in this format is ignored.
<saml2:NameID xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
NameQualifier=https://idpdev.csu.edu.au/idp/shibboleth
SPNameQualifier= https://global.replicon.com/!/saml2/REDACTED
>User1 </saml2:NameID>
Regards
Gary
[1] LogoutRequest from Replicon
<samlp:LogoutRequest ID="_25b26cde-5be7-43a3-87a4-e48ddc5b8789"
Version="2.0"
IssueInstant="2022-03-25T04:12:31.21Z"
Destination=https://idpdev.csu.edu.au/idp/profile/SAML2/Redirect/SLO
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
>
<saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://global.replicon.com/!/saml2/REDACTED%3c/saml:Issuer>
<Signature xmlns=http://www.w3.org/2000/09/xmldsig>
<SignedInfo>
<CanonicalizationMethod Algorithm=http://www.w3.org/2001/10/xml-exc-c14n />
<SignatureMethod Algorithm=http://www.w3.org/2001/04/xmldsig-more#rsa-sha256 />
<Reference URI="#_25b26cde-5be7-43a3-87a4-e48ddc5b8789">
<Transforms>
<Transform Algorithm=http://www.w3.org/2000/09/xmldsig#enveloped-signature />
<Transform Algorithm=http://www.w3.org/2001/10/xml-exc-c14n>
<InclusiveNamespaces PrefixList="#default samlp saml ds xs xsi"
xmlns=http://www.w3.org/2001/10/xml-exc-c14n
/>
</Transform>
</Transforms>
<DigestMethod Algorithm=http://www.w3.org/2001/04/xmlenc#sha256 />
<DigestValue>u45t8I9MlPev68VVqY0kzXciKAiKiySXdQVL3ohrYsM=</DigestValue>
</Reference>
</SignedInfo>
<SignatureValue>REDACTED</SignatureValue>
<KeyInfo>
<X509Data>
<X509Certificate>REDACTED</X509Certificate>
</X509Data>
</KeyInfo>
</Signature>
<saml:NameID xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">User1</saml:NameID>
</samlp:LogoutRequest>
Gary Lipscomb
Technical Officer, Systems | IT Infrastructure & Security | Division of Information Technology
Charles Sturt University
| ALBURY-WODONGA | BATHURST | BRISBANE | CANBERRA | DUBBO | GOULBURN | MELBOURNE | ORANGE | PORT MACQUARIE | SYDNEY | WAGGA WAGGA |
LEGAL NOTICE
This email (and any attachment) is confidential and is intended for the use of the addressee(s) only. If you are not the intended recipient of this email, you must not copy, distribute, take any action in reliance on it or disclose it to anyone. Any confidentiality is not waived or lost by reason of mistaken delivery. Email should be checked for viruses and defects before opening. Charles Sturt University does not accept liability for viruses or any consequence which arise as a result of this email transmission. Email communications with Charles Sturt University may be subject to automated email filtering, which could result in the delay or deletion of a legitimate email before it is read at Charles Sturt University. The views expressed in this email are not necessarily those of Charles Sturt University.
Charles Sturt University in Australia The Grange Chancellery, Panorama Avenue, Bathurst NSW Australia 2795 (ABN: 83 878 708 551). Charles Sturt University - TEQSA Provider Identification: PRV12018 (Australian University). CRICOS Provider: 00005F.
Consider the environment before printing this email.
More information about the users
mailing list