<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link="#0563C1" vlink="#954F72"><div class=WordSection1><p class=MsoNormal>Liam – we created custom .jsp files on our IDP that includes a series of logout calls to critical SPs only (financials, procurement, etc.), and clears one’s SSO session.  However, the practice is not sustainable as service owners update their service and/or SP the logout calls often 404.  <o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Thanks, Jay <o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>________________________________<o:p></o:p></p><p class=MsoNormal>Jason Rappaport<o:p></o:p></p><p class=MsoNormal>Identity and Access Management Analyst<o:p></o:p></p><p class=MsoNormal>Office of Information Technology<o:p></o:p></p><p class=MsoNormal>Email:  <a href="mailto:jasonrap@princeton.edu"><span style='color:windowtext'>jasonrap@princeton.edu</span></a> <o:p></o:p></p><p class=MsoNormal>Office:  609-258-8464<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><b>From:</b> users <users-bounces@shibboleth.net> <b>On Behalf Of </b>Liam Hoekenga<br><b>Sent:</b> Thursday, April 4, 2019 5:16 PM<br><b>To:</b> Shib Users <users@shibboleth.net><br><b>Subject:</b> IDP logout customizations<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><div><p class=MsoNormal>I'd like to talk to list members from institutions that have customized the logout behavior of IDP v3.<o:p></o:p></p><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>We're migrating from a legacy sso solution, and had previously "customized" the provided logout functionality to tie it into the SLO for our legacy solution (more "rip and replace" than customize).<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>After talking to our stakeholders, the desired behavior seems to be..<o:p></o:p></p></div><div><div><p class=MsoNormal>- logout of service provider (kill application and SP sessions)<o:p></o:p></p></div><div><p class=MsoNormal>- kill IDP session<o:p></o:p></p></div><div><p class=MsoNormal>- if service provided a redirect URL, send the user to that location<o:p></o:p></p></div><div><p class=MsoNormal>- user must log in again before they're able to access that service provider<o:p></o:p></p></div></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>I've been in touch with Minnesota and they have some stuff that looks promising, but also requires the alteration of the system logout flows.  I'd like to see what other places have done to try and figure out what we want to do.<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>thanks!<o:p></o:p></p></div><div><p class=MsoNormal>Liam<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div></div></div></body></html>