<div dir="ltr"><div>OK scrub the new problem for now, fixed my metadata which I think has fixed it (Canvas was getting an incorrect fingerprint, and updates every 24 hours).</div><div><br></div><div>What I didn't notice yesterday was that there is a SAML Logout section at the bottom of the Logout setup page, so I've now added the Required line to my idp.properties:</div><div>idp.session.secondaryServiceIndex = true</div><div>(as noted yesterday, I've already enabled track SP sessions + shibboleth.<wbr>ClientPersistentStorageService in that file also)</div><div><br></div><div>I've attached the DEBUG log file for an unsuccessful logout attempt, starting from the decoded request.</div><div>My limited understanding suggests there's a lot of noise from it looking for things in the different metadata providers in there, but didn't want to snip anything in case I missed something important.</div><div><br></div><div><br></div><div>Thanks,<br>Dave<br></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Oct 24, 2017 at 10:28 AM, HCUK eLearning <span dir="ltr"><<a href="mailto:daveperryatwork@gmail.com" target="_blank">daveperryatwork@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid"><div dir="ltr"><div>There is a field for Logout URL when you configure SAML as the authentication type, I don't really want to leave it blank.</div><div><br></div><div>The page I referenced didn't say you had to do more than the 2 things I put. So </div></div><div class="gmail-m_3030551289548676660gmail-HOEnZb"><div class="gmail-m_3030551289548676660gmail-h5"><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Oct 23, 2017 at 4:54 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid"><span>> I've set our Canvas sites up with our v3 IdP. I'm trying to get SLO working (to<br>
> get rid of the horrible 'there was a problem logging out' error Canvas gives<br>
> when you click Log Out), and made the following changes in idp.properties:<br>
<br>
</span>I don't know that Canvas supports SAML logout.<br>
<br>
And those are definitely insufficient changes to make logout work, if you mean full on SAML logout. The changes required are documented in the wiki, and include turning on HTML local storage via that property, and setting idp.session.secondaryServiceIn<wbr>dex = true<br>
<br>
But it depends what kind of logout we're talking about.<br>
<span><br>
> The page I'm looking at<br>
> (<a href="https://wiki.shibboleth.net/confluence/display/IDP30/LogoutConfiguration" target="_blank" rel="noreferrer">https://wiki.shibboleth.net/c<wbr>onfluence/display/IDP30/Logout<wbr>Configuration</a>)<br>
> doesn't seem to mention that I need to do anything else to get the basics<br>
> working. Am I missing something?<br>
<br>
</span>Potentially, yes.<br>
<span class="gmail-m_3030551289548676660gmail-m_6734854159229037165HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br>
</font></span></blockquote></div><br></div>
</div></div></blockquote></div><br></div></div>