Ok, well in that case can I ask that the idp (or how to configure the IdP ) to instead perform the logout but not return to the sp if it's configured for client side sessions? Perhaps just terminate on the local logout page?<div><br></div><div>Dave<span></span><br><br>On Saturday, January 17, 2015, Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Your "bug" is that you're trying to use client-side session storage with logout, which is impossible at present. That only changes if we manage to hack something together with DOM storage as a back-end, cookies will never work. Setting the other properties doesn’t affect storage implementations that don't support them.<br>
<br>
> It's also saying this:<br>
><br>
> 2015-01-16 22:15:30,519 - DEBUG<br>
> [net.shibboleth.idp.saml.profile.impl.ExtractSubjectFromRequest:144] -<br>
> Profile Action ExtractSubjectFromRequest: No Subject NameID or<br>
> NameIdentifier in message<br>
<br>
That's an unfortunate message that doesn't matter for logout requests, the subject doesn't get "decoded" on logouts, the NameID just gets used directly.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="javascript:;" onclick="_e(event, 'cvml', 'users-unsubscribe@shibboleth.net')">users-unsubscribe@shibboleth.net</a></blockquote></div><br><br>-- <br>David Langenberg<div>Identity & Access Management</div><div>The University of Chicago</div><br>