<div dir="ltr">Hi<div><br></div><div>We are currently using Shibboleth&#39;s IDP local logout functionality (/idp/profile/Logout) and it was out understanding that once the user goes to that address the session gets destroyed on Shibboleth side and also the cookie get removed on the user&#39;s browser.</div>
<div><br></div><div>Recently we noticed that the cookie is not being removed from the user&#39;s browser (The session is still destroyed though) and now I am uncertain whether I made an incorrect assumption and it does not actually does that or if we mistakenly broke it due to code changes on logout.jsp</div>
<div><br></div><div>Could someone confirm for me that the original, unmodified Shibboleth IDP 2.4 local logout functionality removes the cookie from the user&#39;s browser or does it only destroy the session on the IDP side?</div>
</div>