<div dir="ltr">Hi<div><br></div><div>We are currently using Shibboleth's IDP local logout functionality (/idp/profile/Logout) and it was out understanding that once the user goes to that address the session gets destroyed on Shibboleth side and also the cookie get removed on the user's browser.</div>
<div><br></div><div>Recently we noticed that the cookie is not being removed from the user's browser (The session is still destroyed though) and now I am uncertain whether I made an incorrect assumption and it does not actually does that or if we mistakenly broke it due to code changes on logout.jsp</div>
<div><br></div><div>Could someone confirm for me that the original, unmodified Shibboleth IDP 2.4 local logout functionality removes the cookie from the user's browser or does it only destroy the session on the IDP side?</div>
</div>