<div dir="ltr">Hi Folks,<div><br></div><div>In our deployment with Shibboleth IDP v3, we have configured SLO from the applications, so that they log out from their applications and then Shibboleth. But there are a few corner cases that have appeared in testing. </div><div><br></div><div>One of the problems is that when an user authenticates with Shibboleth but doesn't have permissions for the application itself. The issue here is that because the user can't get into the application, they can't logout (and hence logout of Shibboleth). And without being able to logout of Shibboleth they can't enter new credentials (assume they have a second set of credentials) to get into the application.</div><div><br></div><div>Is there a way of just logging out of Shibboleth directly in this instance.</div><div>I have been trying the idp/Profile/Logout by calling https://<site>/idp/Profile/Logout without any args and although it goes to the logout page, it doesn't seem to be clearing the necessary sessions.</div><div><br></div><div>Kind regards</div><div>Ranil</div><div><br></div><div>
</div></div>

<br>
<div><font face="Arial, Helvetica, sans-serif" size="2"><br></font></div><font face="Arial, Helvetica, sans-serif" size="2">This email is confidential and intended solely for the person(s) to whom it is addressed.</font>