<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Oct 11, 2016 at 5:45 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div id="m_-8474317882666842103gmail-:gdi" class="m_-8474317882666842103gmail-a3s m_-8474317882666842103gmail-aXjCH m_-8474317882666842103gmail-m157b5ec9f5571449">In that case the error will be in the other log but the bottom line is the metadata's not right.<div class="m_-8474317882666842103gmail-yj6qo m_-8474317882666842103gmail-ajU"><div id="m_-8474317882666842103gmail-:ged" class="m_-8474317882666842103gmail-ajR"></div></div></div></blockquote></div><div class="gmail_extra"><br></div>Should the metadata generated by the SP's metagen.sh or the IDP's metadata endpoint support SLO?</div><div class="gmail_extra"><br>I tried regenerating the SP metadata.</div><div class="gmail_extra"><div class="gmail_extra">I've tried using the SP metadata from InCommon.</div><div>I've fetched a fresh copy of the IDP metadata from the metadata generator.<br></div></div><div class="gmail_extra">Everything has SLO endpoints, and everything agrees on each other's certificates.<br></div><div class="gmail_extra"><br></div><div class="gmail_extra">I turned shibd.log up to DEBUG, and I see the LogoutRequest is generated:</div><div class="gmail_extra"><div class="gmail_extra">2016-10-12 12:46:00 DEBUG OpenSAML.MessageEncoder.<wbr>SAML2Redirect [2]: marshalled message:</div><div class="gmail_extra"><samlp:LogoutRequest xmlns:samlp="urn:oasis:names:<wbr>tc:SAML:2.0:protocol" Destination="<a href="https://idp-mcomm-qa.dsc.umich.edu/idp/profile/SAML2/Redirect/SLO" target="_blank">https://idp-<wbr>mcomm-qa.dsc.umich.edu/idp/<wbr>profile/SAML2/Redirect/SLO</a>" ID="_<wbr>4659ad8e355e35e2d610232589c3d7<wbr>d8" IssueInstant="2016-10-12T16:<wbr>46:00Z" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:<wbr>tc:SAML:2.0:assertion"><a href="https://shib-sp-test.www.umich.edu/shibboleth" target="_blank">https:/<wbr>/shib-sp-test.www.umich.edu/<wbr>shibboleth</a></saml:Issuer></div><div class="gmail_extra">...</div><div class="gmail_extra"></samlp:LogoutRequest><br></div><div class="gmail_extra"><div class="gmail_extra">2016-10-12 12:46:00 DEBUG OpenSAML.MessageEncoder.<wbr>SAML2Redirect [2]: signing the message</div><div class="gmail_extra">2016-10-12 12:46:00 DEBUG OpenSAML.MessageEncoder.<wbr>SAML2Redirect [2]: message encoded, sending redirect to client</div><div><br></div><div>It doesn't get sent to the browser or the IDP.  The SP returns a 500 and the error message:</div><div><br></div><div><div>shibsp::ConfigurationException at (<a href="https://shib-sp-test.www.umich.edu/Shibboleth.sso/Logout" target="_blank">https://shib-sp-test.www.<wbr>umich.edu/Shibboleth.sso/<wbr>Logout</a>)</div><div>None of the configured LogoutInitiators handled the request.</div></div><div><br></div><div><br></div><div>What would cause it to generate the logout request but then not publish it?</div><div><br></div><div>Liam</div><div><br></div></div></div></div>