<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Helvetica;
        panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thanks Nate,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">The complete query string is:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">SAMLRequest=jVPRcqIwFP0VhteOBlBAMsoMrVLp2tqK2q4vnZAESYXEktCqX7%2Bg66x92E5fT8655557b%2FoSFfkWTsRaVGpG3ysqlbYrci7h8WWgVyWHAkkmIUcFlVBhGAf3E2i1DbgthRJY5Lo2rHWMI8UEH%2BiZUlsJAcjFmvF2Vag2JRVgZAtqQcpyCpoKFphRwkqKFYgnU12LhgP9lWC367ou9jpez8BJYiddu4cd0%2B4gRLvUq2lSVjTiUiGuBrplmE7L6LQMb2660LSh5ax0bUlLeeykblL3%2B00SeNSVF9m%2Bj4akpGUTR%2FfPcWrgg2EqDbON5AaRgsnGRbY5VUBmLElETlUG5LYPLixP%2Fls42inKjwK%2Fj2QuYCD3HGel4KKSf%2Ftq8J%2BNHNKdqul1hVat0YF%2F8vxq0yAWfKiLRMOL5NZPo2uhKAukvqc3CCOt9EiFqkS1O%2BVK1xrfpwrlLGW0%2FO4q%2Fs1O1%2BLH%2F8h%2BPn3dDwJyWD0%2F7FcvTzt5MCeBE0YzS4x6YH97exDAeslImE1%2Fydj%2B2FXY%2Bx2%2BLSI0vgPXIxIlZiqK25url8l8tHSWN%2FQ92XiPCDB7uaFRGK3SAi9Csp9OV7lroL2d3i%2Bun3Axc0dzcXU%2FnvJNsGQOcQ93SfC4XqzRHY7HqTVzsv3bc3dOkt4nHV6P43k45g%2FdZTAYnHZ33tT5YGJ6TBhxQnf%2Bq2tbnovttGtZVoI7PWQ69X%2FoIZQQ17GJc97%2FF9UZ%2FPK%2F%2FT8%3D&RelayState=ss%3Amem%3Aafed0010b972f34e5176afceb3f3a2b35bf104556330a2adeada73172508f5ae&SigAlg=http%3A%2F%2Fwww.w3.org%2F2000%2F09%2Fxmldsig%23rsa-sha1&Signature=pd4PeGOt6x6v5zXTsUC5mi55vl99bE7WnFLbdoFjD7YzuTPmGmNCsY8Ng8Kk41m8iT0I6vl9vdGyRx1CVSHnaVhjqsBgUgUSVw1u%2FxPSIhpfJEsJb1YP4qDJDSP7va7%2FynjUuD1m%2Fo6JcroB11M3CD8cumAW4eAOCcdU2XcxsWQIwUPC4eg0EkZB4HFZl0ZWTN1lgfWZKkvEp9C8ri6UTVix31XvTyci7jnRe3nVM7swb137hgac%2BgFKlTxO60x2%2FGPoNtK40FgNA4kMo%2B%2FleXXg3%2BMYOPllMyelLY6WLV8Woy1EIAnNSbcUJqON3Ijw%2FR%2BRTigVIwO3%2Bm%2FppLNneA%3D%3D<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">I understand that the idp/profile/Logout isn’t really SAML2 logout.  It is amazing to me that there are ‘professional’ cloud services out there that offer SAML2
 authentication and have no idea how to configure their SP software for SAML2 logout.  They just say ‘we don’t do that’ and offer to do post-local logout redirect.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thanks again for your time and assistance.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Josh<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> users [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Nate Klingenstein<br>
<b>Sent:</b> Wednesday, March 9, 2016 10:42 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: IdPv3 SLO redirect request failures<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Josh, <o:p></o:p></p>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">We can’t see the full contents of your example because of the ellipsis, but you can literally decode it yourself:<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"><a href="https://rnd.feide.no/software/saml_2_0_debugger/">https://rnd.feide.no/software/saml_2_0_debugger/</a><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">The /idp/profile/Logout page pretty much just clears your session with the IdP if you land on it.  It’s not formal SAML in any way.  The SLO endpoint is formal SAML.  I don’t know the v3 SLO documentation well yet, but this covers the same
 concepts in the first few paragraphs:<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableSLO">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableSLO</a><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Signature issues would be a very good place to start looking.  Unless something is obvious to someone else, the complete query string will be needed for us to see any more.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Take care,<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">Nate.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">{IDP-HOST}/idp/profile/SAML2/Redirect/SLO?SAMLRequest=jVPRcqIwFP0VhteOBlBAMsoMrVLp2tqK2q4vnZAESYXEktCqX7%2Bg66x92E5fT8655557b%2FoSFfkWTsRa%3D…<o:p></o:p></span></p>
</div>
</blockquote>
</div>
</div>
</div>
</body>
</html>