<div dir="ltr">in audit.log there are some differences in the lines with successfull and unsuccessfull attempt to logout:<div><br></div><div>if my app is second in the chain to logout line is (unsuccessfull attempt):</div><div>20171010T144902Z|||<b>urn:ru:pgk:reserve|<a href="http://shibboleth.net/ns/profiles/saml2/logout|idp:shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST">http://shibboleth.net/ns/profiles/saml2/logout|idp:shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</a></b>|_1280486001835c52d3c0ab78561a4141||||AAdzZWNyZXQx5SOLta6p6IsTbuBUoDV9rRSKzP5gzqc2loVF16CEYmB2A32BhqWGCdSOqrSvufT/R0Evukggbo4E1/h1dBKsFckvc4KImWbEV0Imfks4axThuoG/qnSUI6ybrLrKKoPY2AfHQESzgV/7pQ==||<br></div><div><br></div><div>if my app (the same) is first (successfull attempt):</div><div>20171010T144941Z|<b>urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|a2aadi9e48h72dcibi5gcfegh18d76|urn:ru:pgk:reserve|<a href="http://shibboleth.net/ns/profiles/saml2/logout|idp:shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST">http://shibboleth.net/ns/profiles/saml2/logout|idp:shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</a></b>|_e810611e7517db8e7ed57caca59ec2dc||||||<br></div><div><br></div><div>may be problem is in this difference?</div><div><br></div><div>Pavel</div><br><div class="gmail_quote"><div dir="ltr">вт, 10 окт. 2017 г. в 17:35, Павел Шашко <<a href="mailto:pavel.shashko@gmail.com" target="_blank">pavel.shashko@gmail.com</a>>:<br></div></div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">> Where does it say it's unsuccessful?  </div><div dir="ltr"><div>because I can open the second application without authentication</div></div><div dir="ltr"><div><br></div><div>> Your audit log isn't configured usefully enough to tell much of anything </div></div><div dir="ltr"><div>In my logback.xml I see ALL level for IDP_AUDIT appender. How can I improve the quality of the log?</div></div><div dir="ltr"><div><br></div><div>> it's probably working as much as it's ever going to. </div></div><div dir="ltr"><div>before that I had an IDP version without SLO. This is my first attempt to use SLO<br><br><div class="gmail_quote"><div dir="ltr">вт, 10 окт. 2017 г. в 17:04, Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>>:<br></div></div></div></div><div dir="ltr"><div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">> In audit log I see the attempt to logout from my second app. Unsuccessful attempt..<br>
<br>
Where does it say it's unsuccessful?<br>
<br>
> But there is no errors in all logs!<br>
<br>
Your audit log isn't configured usefully enough to tell much of anything, but it's logging a propagation over POST to an SP, and unless that's failing, which there is no evidence to conclude either way, it's probably working as much as it's ever going to.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div></div></div><div dir="ltr">-- <br></div><div class="m_7499901794950846466m_-2044735749070017493gmail_signature" data-smartmail="gmail_signature"><div dir="ltr">С уважением,<div>Павел Шашко</div></div></div></blockquote></div></div><div dir="ltr">-- <br></div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr">С уважением,<div>Павел Шашко</div></div></div>