Ok, well in that case can I ask that the idp (or how to configure the IdP ) to instead perform the logout but not return to the sp if it&#39;s configured for client side sessions?  Perhaps just terminate on the local logout page?<div><br></div><div>Dave<span></span><br><br>On Saturday, January 17, 2015, Cantor, Scott &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt; wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Your &quot;bug&quot; is that you&#39;re trying to use client-side session storage with logout, which is impossible at present. That only changes if we manage to hack something together with DOM storage as a back-end, cookies will never work. Setting the other properties doesn’t affect storage implementations that don&#39;t support them.<br>
<br>
&gt; It&#39;s also saying this:<br>
&gt;<br>
&gt; 2015-01-16 22:15:30,519 - DEBUG<br>
&gt; [net.shibboleth.idp.saml.profile.impl.ExtractSubjectFromRequest:144] -<br>
&gt; Profile Action ExtractSubjectFromRequest: No Subject NameID or<br>
&gt; NameIdentifier in message<br>
<br>
That&#39;s an unfortunate message that doesn&#39;t matter for logout requests, the subject doesn&#39;t get &quot;decoded&quot; on logouts, the NameID just gets used directly.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="javascript:;" onclick="_e(event, &#39;cvml&#39;, &#39;users-unsubscribe@shibboleth.net&#39;)">users-unsubscribe@shibboleth.net</a></blockquote></div><br><br>-- <br>David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div><br>