<html><head></head><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:13px"><div id="yiv2120323985"><div id="yui_3_16_0_1_1458135352541_3102"><div id="yui_3_16_0_1_1458135352541_3101" style="color:#000;background-color:#fff;font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:13px;"><div id="yiv2120323985yui_3_16_0_1_1458135230914_4066">Hi Scott,</div><div id="yui_3_16_0_1_1458135352541_3186"><br clear="none"></div><div id="yui_3_16_0_1_1458135352541_3127"><div id="yui_3_16_0_1_1458135352541_3310"> The truth is I don't want to spend any time on logout, but it isn't my choice. Our SP is Service-Now and their portal has a logout button. When you hit logout a brief screen flashes with the error "Can Validate SAML LogOutResponse", it then puts up a screen that says "Logout successful"<br></div><div id="yui_3_16_0_1_1458135352541_3419"><br></div><div id="yui_3_16_0_1_1458135352541_3532" dir="ltr"> Our CIO is insisting that we eliminate this error. If we could suppress it on the Service Now side that would suffice, but so far Service Now has been unable to come up with a solution, so it's up to me to eliminate the error and right now getting SLO working seems to be the best solution.</div><div id="yui_3_16_0_1_1458135352541_4050" dir="ltr"><br></div><div id="yui_3_16_0_1_1458135352541_3817" dir="ltr"> In the Service Now logs I see:</div><div id="yui_3_16_0_1_1458135352541_3818" dir="ltr"><br></div><div id="yui_3_16_0_1_1458135352541_3745" dir="ltr">Failed to validate logout response status. Expected: urn:oasis:names:tc:SAML:2.0:status:Success, actual: urn:oasis:names:tc:SAML:2.0:status:Requester</div><div id="yui_3_16_0_1_1458135352541_3819" dir="ltr"><br></div><div id="yui_3_16_0_1_1458135352541_3787" dir="ltr">Based on the error in idp-warn.log it's suggesting that it can't find the session, my hope is that getting the session keeping working I'll have my solution. Of course another possible solution would be to have a page that sends back the correct SAML response, but at my current level of knowledge this seems even more difficult than SLO.</div><div dir="ltr"><br></div><div dir="ltr">Regards</div><div id="yui_3_16_0_1_1458135352541_4051" dir="ltr">-Bob<br></div></div><div id="yui_3_16_0_1_1458135352541_3119">--<br clear="none"></div><div id="yiv2120323985yui_3_16_0_1_1458135230914_4068">Bob Lamothe<br clear="none">robert_lamothe@yahoo.com<br clear="none">KB1BOB<br clear="none">603-918-6336<br clear="none"><br clear="none"></div> <div id="yui_3_16_0_1_1458135352541_3280" class="yiv2120323985qtdSeparateBR"><br clear="none"><br clear="none"></div><div class="yiv2120323985yqt0821156987" id="yiv2120323985yqt00954"></div></div></div></div><div class=".yiv2120323985yahoo_quoted"> <div style="font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:13px;"> <div style="font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px;"> <div dir="ltr"><font face="Arial" size="2"> On Tuesday, March 15, 2016 5:54 PM, "Cantor, Scott" <cantor.2@osu.edu> wrote:<br clear="none"></font></div> <br clear="none"><br clear="none"> <div class="yiv2120323985y_msg_container">On 3/15/16, 4:59 PM, "users on behalf of Robert Lamothe" <<a rel="nofollow" shape="rect" ymailto="mailto:users-bounces@shibboleth.net" target="_blank" href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a rel="nofollow" shape="rect" ymailto="mailto:robert_lamothe@yahoo.com" target="_blank" href="mailto:robert_lamothe@yahoo.com">robert_lamothe@yahoo.com</a>> wrote:<br clear="none"><br clear="none"><br clear="none"><br clear="none">> I've solved most of my shib problems but I have one that is proving to be very sticky.<br clear="none"><br clear="none">Logout is not something you want to spend time on unless you're prepared to spend a lot.<div class="yiv2120323985yqt9604419032" id="yiv2120323985yqtfd60622"><br clear="none"><br clear="none">>My SP has a logout button which I've used redirect to point to my SLO.</div><br clear="none"><br clear="none">Are you trying to do a SAML logout or use the proprietary "clear this session" endpoint at /idp/profile/Logout? They are fundamentally different. And that's all separate from the propagation of logout, which is possible for CAS and SAML, but only under very particular circumstances.<br clear="none"><br clear="none">-- Scott<br clear="none"><br clear="none">-- <br clear="none">To unsubscribe from this list send an email to <a rel="nofollow" shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" target="_blank" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><div class="yiv2120323985yqt9604419032" id="yiv2120323985yqtfd75747"><br clear="none"></div><br clear="none"><br clear="none"></div> </div> </div> </div></div></body></html>