<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>Hi list,</p>
    <p>some years back, Zoom used to be unable to sign SLO requests. Now
      they do - however, the IdP would not honor them:<br>
    </p>
    <p>ERROR
      [org.opensaml.security.x509.impl.BasicX509CredentialNameEvaluator:301]
      - Credential failed name check:
      [subjectName='CN=*.zoom.us,OU=Domain Control Validated']</p>
    <p>I suspect it has to do with the wildcard certificate? <br>
    </p>
    <p>What would you advise - toggle off signing SLO requests? Can I
      use idp.logout.authenticated just for one SP? <br>
    </p>
    <p>Or push back?<br>
    </p>
    <p>Regards</p>
    <p>Martin<code class="text plain"><br>
      </code></p>
    <pre class="moz-signature" cols="72">-- 
Dr. Martin Haase, Solutions Engineer

DAASI International GmbH        
Europaplatz 3                   
D-72072 Tübingen                
Germany                    

phone: +49 7071 407109-0
fax:   +49 7071 407109-9  
email: <a class="moz-txt-link-abbreviated" href="mailto:martin.haase@daasi.de">martin.haase@daasi.de</a>
web:   <a class="moz-txt-link-abbreviated" href="http://www.daasi.de">www.daasi.de</a>

Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz
</pre>
  </body>
</html>