<html><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, Sans-Serif;font-size:12pt"><div>Hi,</div><div>&nbsp;I am trying to send a LogoutRequest from SP to IdP, but the request is not fulfilled by IdP.</div><div>idp-process.log says "LogoutRequest did not reference an active session." even though the LogoutRequest contains sessionIndex from Assertion's&nbsp;AuthnStatement.</div><div><br></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; background-color: transparent; font-style: normal;">Here is the LogoutResponse from IdP:</div><div style="background-color: transparent;">&lt;saml2p:LogoutResponse xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://inw00003973:8443/testsp/SSOLogoutServlet"&nbsp;</div><div style="background-color:
 transparent;">ID="_e480d271c81a2e861f53b50648f108b7" InResponseTo="ec61ed5a-4532-4da2-922c-ac97423fc0e2" IssueInstant="2013-11-26T06:39:56.754Z" Version="2.0"&gt;</div><div style="background-color: transparent;">&lt;saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"&gt;https://inw00003973/idp/shibboleth&lt;/saml2:Issuer&gt;</div><div style="background-color: transparent;">&lt;saml2p:Status&gt;&lt;saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Requester"&gt;&lt;saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:UnknownPrin</div><div style="background-color: transparent;">cipal"/&gt;&lt;/saml2p:StatusCode&gt;&lt;/saml2p:Status&gt;&lt;/saml2p:LogoutResponse&gt;</div><div style="background-color: transparent;"><br></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial,
 'Lucida Grande', sans-serif; font-style: normal;">And here is the LogoutRequest (signature/certificate skipped to conserve space):</div><div style="background-color: transparent;">&lt;saml2p:LogoutRequest xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://inw00003973/idp/profi</div><div style="background-color: transparent;">le/SAML2/Redirect/SLO" ID="ec61ed5a-4532-4da2-922c-ac97423fc0e2" IssueInstant="2013-11-26T06:39:56.607Z" Reason="urn:oasis:names:tc:SAML:2.0:logout:user" Version="2.0"&gt;</div><div style="background-color: transparent;">&nbsp; &nbsp;&lt;saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"&gt;https://inw00003973:8443&lt;/saml2:Issuer&gt;</div><div style="background-color: transparent;">&nbsp; &nbsp;&lt;saml2:NameID xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"&gt;vasu@abc.com&lt;/saml2:NameID&gt;</div><div style="background-color:
 transparent;">&nbsp; &nbsp;&lt;saml2p:SessionIndex&gt;_67ddd3bc159b233ba89ee1a00a330890&lt;/saml2p:SessionIndex&gt;</div><div style="background-color: transparent;">&lt;/saml2p:LogoutRequest&gt;</div><div style="background-color: transparent;"><br></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-style: normal;">And here is the decrypted Assertion from successful AuthnRequest:</div><div style="background-color: transparent;">&lt;saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_5f1be83380ec5ffd716fec00477f2491" IssueInstant="2013-</div><div style="background-color: transparent;">11-26T06:39:55.911Z" Version="2.0"&gt;&lt;saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"&gt;https://inw00003973/idp/shibboleth&lt;/saml2:Issuer&gt;</div><div style="background-color:
 transparent;">&lt;saml2:Subject&gt;&lt;saml2:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" NameQualifier="https://inw00003973/idp/shibboleth"</div><div style="background-color: transparent;">&nbsp;SPNameQualifier="https://inw00003973:8443"&gt;vasu@abc.com&lt;/saml2:NameID&gt;&lt;saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"&gt;&lt;saml2:SubjectConfirmationData Address="192.168.1.8" InResponseTo="49815679-033d-439b</div><div style="background-color: transparent;">-97ad-1ebe85d60568" NotOnOrAfter="2013-11-26T06:44:55.911Z" Recipient="https://inw00003973:8443/testsp/AcsServlet"/&gt;&lt;/saml2:SubjectConfirmation&gt;&lt;/saml2:Subject&gt;&lt;saml2:Conditions NotBefore="2013-11-26T06:39:55.911Z" NotOnOrAfter="2</div><div style="background-color:
 transparent;">013-11-26T06:44:55.911Z"&gt;&lt;saml2:AudienceRestriction&gt;&lt;saml2:Audience&gt;https://inw00003973:8443&lt;/saml2:Audience&gt;&lt;/saml2:AudienceRestriction&gt;&lt;/saml2:Conditions&gt;&lt;saml2:AuthnStatement AuthnInstant="2013-11-26T06:39:55.894Z" SessionIndex</div><div style="background-color: transparent;">="_67ddd3bc159b233ba89ee1a00a330890"&gt;&lt;saml2:SubjectLocality Address="192.168.1.8"/&gt;&lt;saml2:AuthnContext&gt;&lt;saml2:AuthnContextClassRef&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport&lt;/saml2:AuthnContextClassRef&gt;&lt;/sam</div><div style="background-color: transparent;">l2:AuthnContext&gt;&lt;/saml2:AuthnStatement&gt;&lt;/saml2:Assertion&gt;</div><div style="background-color: transparent;"><br></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; background-color: transparent; font-style:
 normal;">Here is the idp-process.log:</div><div style="background-color: transparent;">12:09:55.927 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:331] - secondarily indexing user session by name identifier</div><div style="background-color: transparent;">12:09:55.927 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:796] - Encoding response to SAML request 49815679-033d-439b-97ad-1ebe85d60568 from relying party https://inw00003973:8443</div><div style="background-color: transparent;">12:09:55.932 - INFO [Shibboleth-Audit:1028] -
 20131126T063955Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|49815679-033d-439b-97ad-1ebe85d60568|https://inw00003973:8443|urn:mace:shibboleth:2.0:profiles:saml2:sso|https://inw00003973/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_15a6abe08275ebb79e7ddbec5b820ac1|user2|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport||vasu@abc.com||</div><div style="background-color: transparent;">12:09:56.749 - INFO [Shibboleth-Access:73] - 20131126T063956Z|192.168.1.8|inw00003973:443|/profile/SAML2/Redirect/SLO|</div><div style="background-color: transparent;">12:09:56.749 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:86] - shibboleth.HandlerManager: Looking up profile handler for request path: /SAML2/Redirect/SLO</div><div style="background-color: transparent;">12:09:56.749 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:97] - shibboleth.HandlerManager:
 Located profile handler of the following type for the request path: edu.internet2.middleware.shibboleth.idp.profile.saml2.SLOProfileHandler</div><div style="background-color: transparent;">12:09:56.749 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SLOProfileHandler:154] - Processing incoming SAML LogoutRequest</div><div style="background-color: transparent;">12:09:56.750 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SLOProfileHandler:502] - Decoding message with decoder binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect'</div><div style="background-color: transparent;">12:09:56.753 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SLOProfileHandler:516] - Decoded request from relying party 'https://inw00003973:8443'</div><div style="background-color: transparent;">12:09:56.753 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SLOProfileHandler:259] - Querying SessionManager based on
 NameID 'vasu@abc.com|urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress'</div><div style="background-color: transparent;">12:09:56.753 - INFO [edu.internet2.middleware.shibboleth.idp.profile.saml2.SLOProfileHandler:266] - LogoutRequest did not reference an active session.</div><div style="background-color: transparent;">12:09:56.754 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:796] - Encoding response to SAML request ec61ed5a-4532-4da2-922c-ac97423fc0e2 from relying party https://inw00003973:8443</div><div style="background-color: transparent;">12:09:56.775 - INFO [Shibboleth-Audit:1028] -
 20131126T063956Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|ec61ed5a-4532-4da2-922c-ac97423fc0e2|https://inw00003973:8443|urn:mace:shibboleth:2.0:profiles:saml2:logout|https://inw00003973/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_e480d271c81a2e861f53b50648f108b7|user2|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport||vasu@abc.com||</div><div><br></div><div>Thanks,</div><div>Vasu</div></div></body></html>