<html><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, Sans-Serif;font-size:12pt"><div><span>Thanks Scott.</span></div><div style="background-color: transparent;"><span>I am just passing NameId, Name Id Format &nbsp;and Session Index (to Logout Request) that SP received from IdP in the Assertion (upon successful authentication).</span></div><div style="background-color: transparent;"><br clear="none"></div><div style="background-color: transparent;"><span>I am just using mostly the default configurations in Shibboleth IdP as i am new to SAML and Shibboleth IdP. I have attached all my IdP config files. If you can help me locate config issue that might be causing IdP from process Logout Request that will be great.</span></div><div style="background-color: transparent;"><br clear="none"></div><div style="background-color:
 transparent;"><span>Thanks,</span></div><div></div><div><span></span></div><div style="background-color: transparent;">Vasu</div><div><br></div>  <div style="font-family: HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <hr size="1">  <font size="2" face="Arial"> <b><span style="font-weight:bold;">From:</span></b> "Cantor, Scott" &lt;cantor.2@osu.edu&gt;<br> <b><span style="font-weight: bold;">To:</span></b> Shib Users &lt;users@shibboleth.net&gt; <br> <b><span style="font-weight: bold;">Sent:</span></b> Tuesday, 26 November 2013 11:46 PM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: LogoutRequest not fulfilled by IdP<br> </font> </div> <div class="y_msg_container"><br>On 11/26/13, 12:59 PM, "vyal2k" &lt;<a shape="rect" ymailto="mailto:vyal2k@yahoo.com"
 href="mailto:vyal2k@yahoo.com">vyal2k@yahoo.com</a>&gt; wrote:<br clear="none"><br clear="none">&gt;I will go with your suggestion and will use transient NameId.<br clear="none">&gt;But how can i get Logout Request to work/process successfully with<br clear="none">&gt;transient NameId as the user is logging in using LDAP common name and the<br clear="none">&gt;IdP is not able to locate the session with transient NameId?<br clear="none"><br clear="none">I don't know, because I don't have any insight into the problem. If the<br clear="none">session were in the cache, it would work, so either you're corrupting the<br clear="none">NameID in the creation of the logout request or you have a problem with<br clear="none">your IdP deployment that I can't diagnose.<div class="yqt2629774765" id="yqtfd91316"><br clear="none"><br clear="none">-- Scott<br clear="none"></div><br><br></div> </div> </div>  </div></body></html>