<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Thu, Jan 30, 2014 at 12:08 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="im">On 1/29/14, 7:05 PM, &quot;Friedrich Clausen&quot; &lt;<a href="mailto:fred@derf.nl">fred@derf.nl</a>&gt; wrote:<br>

&gt;<br>
&gt;However the AD FS side still complains (generic message, I don&#39;t have<br>
&gt;access to the logs) and I&#39;d like to see the actual SAML logout messages<br>
&gt;sent but, from the NativeSPLogging [2] page, it is not clear to me how to<br>
&gt;accomplish this. I have tried adding<br>
&gt; the following to shibd.logger<br>
<br>
</div>Do not modify transaction log levels. That has nothing to do with shibd<br>
logging or debugging, that&#39;s the audit log.<br>
<br>
Look at shibd.logger:<br>
<br>
# tracing of SAML messages and security policies<br>
#log4j.category.OpenSAML.MessageDecoder=DEBUG<br>
#log4j.category.OpenSAML.MessageEncoder=DEBUG<br></blockquote><div><br></div><div>Thanks Scott - that did the trick.</div><div><br></div><div>Cheers,</div><div><br>Fred.</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br></div></div>