<div dir="ltr"><div><div><div><div><div><div><div><div><div><div>Hello list,<br><br></div>Newbie here. I'm attempting to setup a simple SAML 2.0 federation with:<br><br></div>IdP: MS Server 2008 R2 with ADFS 2.0<br></div>
SP: MS Win 7 with Shibboleth 2.5.3 win 64<br><br></div>I based my tests on the following link <a href="https://wiki.shibboleth.net/confluence/download/attachments/4358293/ADFS_and_Shib.pdf?api=v2">https://wiki.shibboleth.net/confluence/download/attachments/4358293/ADFS_and_Shib.pdf?api=v2</a><br>
<br></div>So far, I was able to get the SSO working (with some issues) but I'm unable to get the Logout done. And yes, I've read the SLO issues article (not sure I get the whole picture though)<br><br></div>-First the SSO issues:<br>
<br></div>Once logged in, if I close my IE10 and then reopen it again, when requesting the /secure URL, I still have a valid session with the IdP (different Shib session ID though) so my IdP creds are not required ( which is undesired). If I use chrome, that behavior does not hold and my creds are indeed requested. This happens consistently even if I clear the cache on both browsers.<br>
<br></div><div>The window events registered with the IE10 case are:<br><br>1) The computer attempted to validate the credentials for an account.<br><br>Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0<br><br>
2) Special privileges assigned to new logon. (with reference to my account in that domain)<br><br>3) An account was successfully logged on.<br><br></div><div>I'm using windows authentication at the /adfs/ls site (extended protection off)<br>
</div><div><br></div>-Next the SLO issues:<br></div>I'm trying to logout with an invocation from my SP that looks like this:<br><br><a href="<a href="https://mySP/Shibboleth.sso/SAML2/POST">https://mySP/Shibboleth.sso/SAML2/POST</a>"><b>IdP Logout</b></a><br>
<br></div>And as a response I get:<br><p class="" style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
"opensaml::BindingException at (<a href="https://mySP/Shibboleth.sso/SAML2/POST">https://mySP/Shibboleth.sso/SAML2/POST</a>)</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
Invalid HTTP method (GET)."</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
The windows event viewer shows the following events:</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
1) Special privileges assigned to new logon (security ID: system)</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
2) An account was successfully logged on (security ID: NULL)</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
3) An account was logged off. (security ID: system)</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
4) The computer attempted to validate the credentials for an account. Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
5) Special privileges assigned to new logon (securityID: my domain account)</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
6) An account was successfully logged on. (security ID: NULL)</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
7) An account was logged off.(securityID: my domain account)</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
8) A Kerberos service ticket was requested.</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
Some relevant config snippets are:</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
Shibboleth2.xml</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
<SSO entityID="<a href="http://myIdP/adfs/services/trust">http://myIdP/adfs/services/trust</a>"><br> <!--discoveryProtocol="SAMLDS" discoveryURL="<a href="https://ds.example.org/DS/WAYF">https://ds.example.org/DS/WAYF</a>"> --><br>
SAML2 SAML1<br> </SSO><br><br> <!-- SAML and local-only logout. --><br> <Logout> SAML2 Local</Logout><br></p><div>I was able to hook in an app proxy that shows the following events after I tried the logout:<br>
<br></div><div>1) a POST to <a href="https://mySP/Shibboleth.sso/SAML2/POST">https://mySP/Shibboleth.sso/SAML2/POST</a> with a 302 Moved redirection<br><br></div><div>2) a GET to <a href="https://mySP/secure">https://mySP/secure</a> with a 401 Unauthorized<br>
<br></div><div>3) idem 2<br><br></div><div>4) a GET to <a href="https://mySP/secure">https://mySP/secure</a> with a 301 Moved Permanently<br><br></div><div>5) and a GET to <a href="https://mySP/secure">https://mySP/secure</a> with a 200 OK<br>
<br></div><div>I'm probably not submitting enough info for you to diagnose what I'm doing wrong, but I'm willing to submit whatever necessary.<br><br></div><div>Any hint will be much appreciated.<br><br><br></div>
<div>Thanks!</div><div><div><div><div><br></div></div></div></div></div>