<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><br></div>Thanks Scott.<div>Yes I do mean /Session not /Status….</div><div><br></div><div><br></div><div>This is fixable as we have full control over the IdP, SP & App provided the IdP can be configured to supply it. What I've just realised is that NameID is not what I thought it was - I had simply configured an attribute called 'NameID' and was loading the users login ID into that.</div><div><br></div><div>I can't find any sample metadata that shows how this is done but are looking at <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPNameIdentifier">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPNameIdentifier</a> but am still confused as to how I configure this - apologies but please bare with me a little longer….</div><div><br></div><div>The sole use of this is for the logout process - so ideally this should be set to a transient value I think?</div><div><br></div><div>Can anyone point me at an example where this is configured?</div><div><br></div><div><br></div><div>Thx……</div><div><br></div><div><br></div><div>jf</div><div><br></div><div><br></div><div><br></div><div><br></div><div><br><div><div>On 12 Jun 2013, at 19:32, "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><blockquote type="cite">The /Status page shows that I have NameID set to the users login name -<br></blockquote><br>I think you mean /Session, but no, it doesn't. It won't show anything about the NameID, it doesn't know what the assertion's subject contained. The problem is as it said, the IdP is not supplying a NameID in the assertion.<br><br><blockquote type="cite">does the message mean that I have to have NameID & entityID set as I read<br>it that either will do?<br></blockquote><br>Both, not neither. But the entityID isn't the problem, that's more of a sanity check. The problem is the NameID isn't supplied.<br><br>If that's not fixable, then you'd have to do with the proprietary option, SAML logout requires a NameID.<br><br>-- Scott<br><br><br><br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div></body></html>