<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Thu, Jan 30, 2014 at 12:08 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="im">On 1/29/14, 7:05 PM, "Friedrich Clausen" <<a href="mailto:fred@derf.nl">fred@derf.nl</a>> wrote:<br>
><br>
>However the AD FS side still complains (generic message, I don't have<br>
>access to the logs) and I'd like to see the actual SAML logout messages<br>
>sent but, from the NativeSPLogging [2] page, it is not clear to me how to<br>
>accomplish this. I have tried adding<br>
> the following to shibd.logger<br>
<br>
</div>Do not modify transaction log levels. That has nothing to do with shibd<br>
logging or debugging, that's the audit log.<br>
<br>
Look at shibd.logger:<br>
<br>
# tracing of SAML messages and security policies<br>
#log4j.category.OpenSAML.MessageDecoder=DEBUG<br>
#log4j.category.OpenSAML.MessageEncoder=DEBUG<br></blockquote><div><br></div><div>Thanks Scott - that did the trick.</div><div><br></div><div>Cheers,</div><div><br>Fred.</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br></div></div>