<div dir="ltr">I&#39;m trying to help one of our departments do a shib integration with Adobe Experience Manager (AEM)<div><br></div><div>There&#39;s a sort of useful document available at...</div><div><br></div><div>    <a href="http://helpx.adobe.com/experience-manager/kb/saml-demo.html">http://helpx.adobe.com/experience-manager/kb/saml-demo.html</a><br></div><div><br></div><div>It&#39;s mostly working, but they&#39;re very interested in having SLO work, and it&#39;s acting pretty weird.</div><div><br></div><div><div>Adobe&#39;s suggestion for the proper SingleLogoutService URL seems sketchy...</div><div><code class="">&lt;</code><code class="">md:SingleLogoutService</code> <code class="">Binding</code><code class="">=</code><code class="">&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot;</code> <code class="">Location</code><code class="">=</code><code class="">&quot;<a href="https://www.blogsaml.com:8443/idp/Authn/UserPassword">https://www.blogsaml.com:8443/idp/Authn/UserPassword</a>&quot;</code><code class="">/&gt;</code></div></div><div><br></div><div>It&#39;s weird to me that the SP&#39;s metadata would define a SingleLogoutService with a URL pointing to a specific IdP.  Weirder yet that they would point to the authentication handler URL?</div><div><br></div><div>Liam</div></div>