<div dir="ltr"><div><div><div><div><div><div><div><div><div><div>Hello list,<br><br></div>Newbie here. I&#39;m attempting to setup a simple SAML 2.0 federation  with:<br><br></div>IdP: MS Server 2008 R2 with ADFS 2.0<br></div>
SP: MS Win 7 with Shibboleth 2.5.3 win 64<br><br></div>I based my tests on the following link <a href="https://wiki.shibboleth.net/confluence/download/attachments/4358293/ADFS_and_Shib.pdf?api=v2">https://wiki.shibboleth.net/confluence/download/attachments/4358293/ADFS_and_Shib.pdf?api=v2</a><br>
<br></div>So far, I was able to get the SSO working (with some issues) but I&#39;m unable to get the Logout done. And yes, I&#39;ve read the SLO issues article (not sure I get the whole picture though)<br><br></div>-First the SSO issues:<br>
<br></div>Once logged in, if I close my IE10 and then reopen it again, when requesting the /secure URL, I still have a valid session with the IdP (different Shib session ID though) so my IdP creds are not required ( which is undesired). If I use chrome, that behavior does not hold and my creds are indeed requested. This happens consistently even if I clear the cache on both browsers.<br>
<br></div><div>The window events registered with the IE10 case are:<br><br>1) The computer attempted to validate the credentials for an account.<br><br>Authentication Package:    MICROSOFT_AUTHENTICATION_PACKAGE_V1_0<br><br>
2) Special privileges assigned to new logon. (with reference to my account in that domain)<br><br>3) An account was successfully logged on.<br><br></div><div>I&#39;m using windows authentication at the /adfs/ls site (extended protection off)<br>
</div><div><br></div>-Next the SLO issues:<br></div>I&#39;m trying to logout with an invocation from my SP that looks like this:<br><br>&lt;a href=&quot;<a href="https://mySP/Shibboleth.sso/SAML2/POST">https://mySP/Shibboleth.sso/SAML2/POST</a>&quot;&gt;&lt;b&gt;IdP Logout&lt;/b&gt;&lt;/a&gt;<br>
<br></div>And as a response I get:<br><p class="" style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
&quot;opensaml::BindingException at (<a href="https://mySP/Shibboleth.sso/SAML2/POST">https://mySP/Shibboleth.sso/SAML2/POST</a>)</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
Invalid HTTP method (GET).&quot;</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
The windows event viewer shows the following events:</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
1) Special privileges assigned to new logon (security ID: system)</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
2) An account was successfully logged on (security ID: NULL)</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
3) An account was logged off. (security ID: system)</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
4) The computer attempted to validate the credentials for an account. Authentication Package:    MICROSOFT_AUTHENTICATION_PACKAGE_V1_0</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
5) Special privileges assigned to new logon (securityID: my domain account)</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
6) An account was successfully logged on. (security ID: NULL)</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
7) An account was logged off.(securityID: my domain account)</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
8) A Kerberos service ticket was requested.</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
Some relevant config snippets are:</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
Shibboleth2.xml</p><p style="color:rgb(0,0,0);font-family:&#39;Times New Roman&#39;;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
            &lt;SSO entityID=&quot;<a href="http://myIdP/adfs/services/trust">http://myIdP/adfs/services/trust</a>&quot;&gt;<br>                 &lt;!--discoveryProtocol=&quot;SAMLDS&quot; discoveryURL=&quot;<a href="https://ds.example.org/DS/WAYF">https://ds.example.org/DS/WAYF</a>&quot;&gt; --&gt;<br>
              SAML2 SAML1<br>            &lt;/SSO&gt;<br><br>            &lt;!-- SAML and local-only logout. --&gt;<br>            &lt;Logout&gt; SAML2 Local&lt;/Logout&gt;<br></p><div>I was able to hook in an app proxy that shows the following events after I tried the logout:<br>
<br></div><div>1) a POST to <a href="https://mySP/Shibboleth.sso/SAML2/POST">https://mySP/Shibboleth.sso/SAML2/POST</a> with a 302 Moved redirection<br><br></div><div>2) a GET to <a href="https://mySP/secure">https://mySP/secure</a> with a 401 Unauthorized<br>
<br></div><div>3) idem 2<br><br></div><div>4) a GET to <a href="https://mySP/secure">https://mySP/secure</a> with a 301 Moved Permanently<br><br></div><div>5) and a GET to <a href="https://mySP/secure">https://mySP/secure</a> with a 200 OK<br>
<br></div><div>I&#39;m probably not submitting enough info for you to diagnose what I&#39;m doing wrong, but I&#39;m willing to submit whatever necessary.<br><br></div><div>Any hint will be much appreciated.<br><br><br></div>
<div>Thanks!</div><div><div><div><div><br></div></div></div></div></div>