<html><head></head><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:13px"><div id="yui_3_16_0_1_1458135352541_18406" dir="ltr">Ok, so, idp.session.trackSPSessions and idp.session.secondaryServiceIndex properties were already set to true, but service side storage was not, so I set idp.session.StorageService = shibboleth.StorageService. On the SP I'm getting the same error, but on the IDP I'm now getting:</div><div id="yui_3_16_0_1_1458135352541_18407" dir="ltr"><br></div><div id="yui_3_16_0_1_1458135352541_18404" dir="ltr">2016-03-16 10:35:28,450 - INFO [net.shibboleth.idp.saml.saml2.profile.impl.ProcessLogoutRequest:315] - Profile Action ProcessLogoutRequest: No active session(s) found matching LogoutRequest<br><br></div><div id="yui_3_16_0_1_1458135352541_18260"><span></span>Regards</div><div id="yui_3_16_0_1_1458135352541_18435">-Bob<br></div><div id="yui_3_16_0_1_1458135352541_18216" class="signature"><div id="yui_3_16_0_1_1458135352541_18215">--<br>Bob Lamothe<br>robert_lamothe@yahoo.com<br>KB1BOB<br>603-918-6336<br><br></div></div> <div class="qtdSeparateBR"><br><br></div><div style="display: block;" class="yahoo_quoted"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 13px;"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div dir="ltr"><font face="Arial" size="2"> On Wednesday, March 16, 2016 10:05 AM, "Cantor, Scott" <cantor.2@osu.edu> wrote:<br></font></div> <br><br> <div class="y_msg_container">On 3/16/16, 9:48 AM, "users on behalf of Robert Lamothe" <<a shape="rect" ymailto="mailto:users-bounces@shibboleth.net" href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a shape="rect" ymailto="mailto:robert_lamothe@yahoo.com" href="mailto:robert_lamothe@yahoo.com">robert_lamothe@yahoo.com</a>> wrote:<br clear="none"><br clear="none"><br clear="none"><br clear="none">> In the Service Now logs I see:<br clear="none">><br clear="none">>Failed to validate logout response status. Expected: urn:oasis:names:tc:SAML:2.0:status:Success, actual: urn:oasis:names:tc:SAML:2.0:status:Requester<br clear="none"><br clear="none">Ok, so it's a SAML logout and it's returning a failure status, so that's good, it means all the basic machinery is working.<br clear="none"><br clear="none">>Based on the error in idp-warn.log it's suggesting that it can't find the session, my hope is that getting the session keeping working I'll have my solution.<br clear="none"><br clear="none">If it's a SAML logout, the requirements for that are:<br clear="none"><br clear="none">- you must set the idp.session.trackSPSessions and idp.session.secondaryServiceIndex properties to true<br clear="none">- you must use a server side storage service, or enable htmlLocalStorage to use the default client side service<br clear="none"><br clear="none">If you don't do that, the expected outcome would be what you're getting.<br clear="none"><br clear="none">I will take a pass over Marvin's draft docs in the wiki and try and clarify some things, I haven't had time to do it yet.<div class="yqt1099065809" id="yqtfd49106"><br clear="none"><br clear="none">-- Scott<br clear="none"><br clear="none">-- <br clear="none">To unsubscribe from this list send an email to <a shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br clear="none"></div><br><br></div> </div> </div> </div></div></body></html>