<div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr">I'm having no luck with SLO either and it also seems related to CSP configuration issues.<div><br></div><div>I was thinking about starting a new thread but I feel like my setup might be similar to Bob's. We have a fairly new deployment that doesn't have a huge amount of configuration legacy so should be pretty simple to get SLO working. I set idp.session.trackSPSessions = true and tried SLO by entering the the <a href="https://idp.mit.c3.ca/idp/profile/Logout">https://myidpurl/idp/profile/Logout</a>. After choosing Yes I get the view that shows the attempt to log out of my test SP was unsuccessful and see the red x beside the SP EntityId. In the chrome dev tools I see this error:</div><div>Refused to display '<a href="https://myidpurl/idp/profile/PropagateLogout?SessionKey=1">https://myidpurl/idp/profile/PropagateLogout?SessionKey=1</a>' in a frame because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'none'".<br></div><div><br></div><div>I had been migrating configuration so I was missing the commented out configuration for frameoptions and scp. I recently added this to my idp.properties and tested SLO again</div><div><div>idp.frameoptions = SAMEORIGIN</div><div>idp.csp = frame-ancestors 'self';</div></div><div><br></div><div>I also tried with</div><div>idp.csp =</div><div><br></div><div>No dice and the exact same error messages are displayed in chrome dev console. I tried with firefox as well and I don't see the red X but SLO also fails with the console message:</div><div><div class="gmail-webconsole-output"><div class="gmail-message gmail-javascript gmail-log gmail-warn"><span class="gmail-message-body-wrapper"><span class="gmail-message-flex-body"><span class="gmail-message-body gmail-devtools-monospace">Content Security Policy: Ignoring ‘x-frame-options’ because of ‘frame-ancestors’ directive.</span> </span></span><br></div><div class="gmail-message gmail-javascript gmail-log error"><span class="gmail-icon" title="Error"></span><span class="gmail-message-body-wrapper"><span class="gmail-message-flex-body"><span class="gmail-message-body gmail-devtools-monospace">Content Security Policy: The page’s settings blocked the loading of a resource at <a href="https://myidpurl/idp/profile/Logout?execution=e2s2">https://myidpurl/idp/profile/Logout?execution=e2s2</a> (“frame-ancestors”).</span></span></span><br></div><div class="gmail-message gmail-javascript gmail-log error"><span class="gmail-message-body-wrapper"><span class="gmail-message-flex-body"><span class="gmail-message-body gmail-devtools-monospace"><br></span></span></span></div><div class="gmail-message gmail-javascript gmail-log error">The only weird thing about my Shibboleth IdP setup is we run it in a Docker container under Kubernetes. TLS is terminated by the ingress controller (Nginx reverse proxy) and there is a HAProxy in front of the entire cluster.</div></div></div></div></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Apr 15, 2019 at 9:24 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> >> Refused to load<br>
> <a href="https://www.mail.allisonr.us:4443/idp/profile/SAML2/Redirect/SLO?SAMLRes" rel="noreferrer" target="_blank">https://www.mail.allisonr.us:4443/idp/profile/SAML2/Redirect/SLO?SAMLRes</a><br>
> ponse=... because it does not appear in the frame-ancestors directive of the<br>
> Content Security Policy.<br>
<br>
The logout endpoint isn't itself implemented under the denial headers, so that doesn't make any sense unless you have unreleased pre-3.4 code in web.xml that hadn't been corrected to exclude the SLO paths. That was fixed before 3.4.0 was done according to the history in git.<br>
<br>
> When I tried to set values in idp.frameoptions and idp.csp to adjust the frame<br>
> options, the values I placed in the properties appears to be ignored.<br>
<br>
It does not ignore them, though it's not reloadable.<br>
<br>
> There are two other things on my to-do list for desired functionality, any<br>
> pointers on these would also be appreciated:<br>
> >> Get the SP to notify my application of the logout so it can clear its<br>
> >> session (I am failing to be able to place a <Notify /> tag in the right place)<br>
<br>
The right place is wherever its documented to go. I have no memory of that, but whatever the schema says and the documentation says is where it goes. I don't think it's very strict.<br>
<br>
> Adjust the logout process so that, as I see at most of the banks and health care<br>
> sites I visit, the SAML SLO is a series of blank pages ending with a page that just<br>
> says "You are logged out. Please close your browser."<br>
<br>
Full frame redirects are a non-starter. That terminates at the first broken system. Logout is aso not interoperable, the specification does not cover the UI sufficiently to make it work. But propagation is only passably acceptable when it's done with frames, and that means the IdP has to control the UI, and SP to IdP is the only full window redirect expected within the UI implemented by these two software products. The SP is more agnostic about it, but it works well enough because there is no particular UI implemented in it anyway and it clears its own state first before giving up control.<br>
<br>
-- Scott<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><p style="margin-bottom:0in;line-height:13px"><font color="#ff0000"><font face="arial, sans-serif"><font style="font-size:10pt"><b>Darren Boss</b></font></font></font></p><font style="font-size:10pt"><i>Senior Programmer/Analyst</i></font><font style="font-size:10pt"><i><br>Programmeur-analyste principal</i></font><font style="font-size:10pt"><i><br><a href="mailto:darren.boss@computecanada.ca" style="color:rgb(17,85,204)" target="_blank">darren.boss@computecanada.ca</a></i></font><font style="font-size:10pt"><i><br>(o) 416.228.1234 x </i></font><font color="#000000"><font style="font-size:10pt">230<br></font></font></div><font color="#000000"><font style="font-size:10pt"><i>(c) 919.525.0083</i></font></font></div></div></div></div>