<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Oct 13, 2016 at 11:51 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div id="gmail-:log" class="gmail-a3s gmail-aXjCH gmail-m157bef51eac669ac">It makes no sense. Even if the Apache server was preventing the requests, you can't possibly get it to go all the way through processing the request (which the logs show it did) and then have it fail.<br></div></blockquote></div><div class="gmail_extra"><br></div><div class="gmail_extra">If the <Location '/Shibboleth.sso'> block is missing "Satisfy Any" and "Allow from all", apache logs / displays:</div><div class="gmail_extra">[Thu Oct 13 13:14:19 2016] [error] [client xxx.xxx.xxx.xxx] None of the configured LogoutInitiators handled the request.<br></div><div class="gmail_extra"><br></div><div class="gmail_extra">If the location block is configured correctly (based on /etc/shibboleth/apache22.config), it proceeds.  I'm still getting a error (a certificate disagreement), but at least it's talking to the IDP.</div><div class="gmail_extra"><br></div>This is a redhat 6.8 machine, with Apache HTTPd 2.2.15.</div><div class="gmail_extra"><br></div><div class="gmail_extra">Liam<br><br></div></div>