Thanks, Scott. I'll disable asynchronous logout.
<br/><br/>On 4/2/2013 10:10 AM, Cantor, Scott E. [via Shibboleth] wrote:
<div class='shrinkable-quote'><br/>&gt; On 4/2/13 8:36 AM, &quot;bmontgomery&quot; &lt;[hidden email]
<br/>&gt; &lt;/user/SendEmail.jtp?type=node&amp;node=7585791&amp;i=0&gt;&gt; wrote:
<br/>&gt;
<br/>&gt; &nbsp;&gt;We have the Shib SP running on IIS, and we're trying to integrate the
<br/>&gt; &nbsp;&gt;logout
<br/>&gt; &nbsp;&gt;functionality with ADFS. I've seen plenty of things out there (including
<br/>&gt; &nbsp;&gt;Shibboleth SP docs) which say that ADFS does not like the extensions
<br/>&gt; &nbsp;&gt;(which
<br/>&gt; &nbsp;&gt;define asynchronous logout) that are put into the XML of the logout
<br/>&gt; &nbsp;&gt;request,
<br/>&gt; &nbsp;&gt;and it throws an error when the user is redirected to ADFS from Shib. I'm
<br/>&gt; &nbsp;&gt;of
<br/>&gt; &nbsp;&gt;the opinion that this is a Microsoft bug, but MS seems to think
<br/>&gt; otherwise.
<br/>&gt;
<br/>&gt; MS is wrong. Extensions in SAML are optional by definition. This is
<br/>&gt; explicitly called out in the standard. This is not just opinion, as it's
<br/>&gt; not an ambiguous area of the standard.
<br/>&gt;
<br/>&gt; &nbsp;&gt;
<br/>&gt; &nbsp;&gt;
<br/>&gt; &nbsp;&gt;&gt;From what I'm reading, I can just put asynchronous=&quot;false&quot; on the
<br/>&gt; &nbsp;&gt;LogoutInitiator element to work around this problem. I'm wondering if
<br/>&gt; that
<br/>&gt; &nbsp;&gt;is the right thing to do. What effect does this have on Shib IdP's (and
<br/>&gt; &nbsp;&gt;other IdP's) which integrate with us?
<br/>&gt;
<br/>&gt; The only software that will ever do anything with that extension is a
<br/>&gt; Shibboleth IdP version that isn't out yet.
<br/>&gt;
<br/>&gt; -- Scott
<br/>&gt;
<br/>&gt;
<br/>&gt; --
<br/>&gt; To unsubscribe from this list send an email to [hidden email]
<br/>&gt; &lt;/user/SendEmail.jtp?type=node&amp;node=7585791&amp;i=1&gt;
<br/>&gt;
<br/>&gt;
<br/>&gt; ------------------------------------------------------------------------
<br/>&gt; If you reply to this email, your message will be added to the discussion
<br/>&gt; below:
<br/>&gt; <a href="http://shibboleth.1660669.n2.nabble.com/Asynchronous-Logout-with-ADFS-tp7585790p7585791.html" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/Asynchronous-Logout-with-ADFS-tp7585790p7585791.html</a><br/>&gt;
<br/>&gt; To unsubscribe from Asynchronous Logout with ADFS, click here
<br/>&gt; &lt;<a href="" target="_top" rel="nofollow" link="external">
<br/>&gt; NAML
<br/>&gt; &lt;<a href="http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&amp;id=instant_html%21nabble%3Aemail.naml&amp;base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&amp;breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml</a>&gt;
<br/>&gt;
</div><br/>

        
        
        
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/Asynchronous-Logout-with-ADFS-tp7585790p7585792.html">Re: Asynchronous Logout with ADFS</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">Shibboleth - Users mailing list archive</a> at Nabble.com.<br/>