<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Jan 20, 2015 at 7:37 AM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">&gt; Ok, so the v3 IdP, by default, is set to use client-side sessions, the auto-<br>
&gt; generated metadata has the logout endpoints advertised, and the docs<br>
&gt; currently written seem to encourage the deployer to stick with client-side<br>
&gt; sessions.<br>
<br>
</span>Defaults are just defaults. People need to use what they think they need to use. There&#39;s no discussion on logout yet because it&#39;s not really implemented more than before, so the impact on settings isn&#39;t really documented to this point.<br>
<span class=""><br>
&gt;  I would very much appreciate it if the IdP would do something<br>
&gt; more in this case than sending the SP the generic message of &quot;An error has<br>
&gt; occurred.&quot;  Ideally, the IdP would either kill the session cookies in the<br>
&gt; browser and display some kind of &quot;you only think you&#39;ve SLO&#39;d&quot; message or<br>
&gt; something a little more detailed would show up in the process log / be sent<br>
&gt; to the SP describing &quot;client-side sessions are not compatible with logout&quot;.<br>
<br>
</span>That will be a fair bit of work, so you&#39;d best file a bug to track it.<br></blockquote><div><br></div><div>IDP-576 created for those following along at home who want to watch it.</div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class=""><br>
&gt; I am interested though in the specific event to trap in the meantime.<br>
<br>
</span>Once I have time to research what actually gets triggered, I can put that into the issue filed.<br></blockquote><div><br></div><div>Sounds good, thanks for the help.</div><div><br>Dave</div><div><br></div></div><div><br></div>-- <br><div class="gmail_signature">David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div></div>
</div></div>