<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
Hello,<br>
<br>
We have a sign out problem in our messaging system which uses ADFS -
Shibboleth IdPV3 authentification.<br>
The Exchange mail server use ADFS which redirects users to
Shibboleth IdP(l'authentification CAS), when we sign out, we get a
randomise error like below :<br>
<br>
<img src="cid:part1.69B1D108.5DCBF0D6@univ-lyon2.fr" alt=""><br>
<br>
Here are the Fiddler logs :<br>
<img src="cid:part2.4183C49E.5342E201@univ-lyon2.fr" alt=""><br>
<b><br>
SAMLRequest for Sign out :</b><br>
<br>
<i><span lang="EN-US"><samlp:LogoutRequest
ID="_f7d76412-06f5-4cfb-8b37-a7a62f792fef" Version="2.0"
IssueInstant="2018-09-20T10:18:02.910Z" Destination=<a
class="moz-txt-link-rfc2396E"
href="https://idp.univ-lyon2.fr/idp/profile/SAML2/Redirect/SLO">"https://idp.univ-lyon2.fr/idp/profile/SAML2/Redirect/SLO"</a>
Consent="urn:oasis:names:tc:SAML:2.0:consent:unspecified"
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"></span></i><br>
<i> </i><i><span lang="EN-US"> <Issuer
xmlns="urn:oasis:names:tc:SAML:2.0:assertion"><a
class="moz-txt-link-freetext"
href="http://adfs.univ-lyon2.fr/adfs/services/trust">http://adfs.univ-lyon2.fr/adfs/services/trust</a></Issuer></span></i><br>
<i> </i><i><span lang="EN-US"> <NameID
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
NameQualifier=<a class="moz-txt-link-rfc2396E"
href="https://idp.univ-lyon2.fr/idp/shibboleth">"https://idp.univ-lyon2.fr/idp/shibboleth"</a>
SPNameQualifier=<a class="moz-txt-link-rfc2396E"
href="http://adfs.univ-lyon2.fr/adfs/services/trust">"http://adfs.univ-lyon2.fr/adfs/services/trust"</a>
xmlns="urn:oasis:names:tc:SAML:2.0:assertion">AAlzZWNyZXQ0NDWvbXX0MaOLdC89vd9egsbPsQgrOw9dAFtEf2eu5BuB8MRVMrnfXFPfDh8MtP+ZExLNZESISJhvlxxGovzgnyYeuOV3r1i90KULY01L/10UhQT7XyvLGhVfHBfdfaMl9FTxoRyK4U0mgT2CK7yzR+maPQ==</NameID></span></i><br>
<i> </i><i><span lang="EN-US">
<samlp:SessionIndex>_f8949ec4f3107c08812844976863ed16</samlp:SessionIndex></span></i><br>
<i> </i><i></samlp:LogoutRequest></i><br>
<br>
<b><i>SAMLResponse of Shibboleth IdP :</i></b><br>
<br>
<i><?xml version="1.0" encoding="UTF-8"?></i><i><br>
</i><i> <saml2p:LogoutResponse Destination=<a
class="moz-txt-link-rfc2396E"
href="https://adfs.univ-lyon2.fr/adfs/ls/">"https://adfs.univ-lyon2.fr/adfs/ls/"</a>
ID="_0241278326194786fbd477e342f3c177"
InResponseTo="_f7d76412-06f5-4cfb-8b37-a7a62f792fef"
IssueInstant="2018-09-20T10:18:03.220Z" Version="2.0"
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"></i><i><br>
</i><i> </i><i><span lang="EN-US"><saml2:Issuer
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"><a
class="moz-txt-link-freetext"
href="https://idp.univ-lyon2.fr/idp/shibboleth">https://idp.univ-lyon2.fr/idp/shibboleth</a></saml2:Issuer></span></i><i><br>
</i><i> </i><i><span lang="EN-US">
<saml2p:Status></span></i><i><br>
</i><i> </i><i><span lang="EN-US">
<saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Requester"></span></i><i><br>
</i><i> </i><i><span lang="EN-US">
<saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:<font
color="#ff0000"><b><u>UnknownPrincipal</u></b></font>"/></span></i><i><br>
</i><i> </i><i><span lang="EN-US">
</saml2p:StatusCode></span></i><i><br>
</i><i> </i><i><span lang="EN-US">
<saml2p:StatusMessage><b>An error occurred</b>.</saml2p:StatusMessage></span></i><i><br>
</i><i> </i><i><span lang="EN-US"> </span></i><i></saml2p:Status></i><i><br>
</i><i> </saml2p:LogoutResponse></i><i><span lang="EN-US"></span></i><br>
<br>
We have the log below in ADFS :<br>
<b><img src="cid:part9.345DC30F.F290F5AE@univ-lyon2.fr" alt=""><br>
</b><br>
Apparently, Shibboleth does not seem to find "Principal" that sends
to ADFS.<br>
Any help would be much appreciated. <br>
<br>
Best regards,
<pre class="moz-signature" cols="72">Marc SAHIN
Administrateur Systèmes
Pôle Système - DSI - Université Lumière Lyon 2
04 78 77 26 66
</pre>
</body>
</html>