<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
There was a message on this list in February :<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
"Has anyone ever had success getting SLO to work with Azure?"</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I'd like to repeat the same question, as I am having problems.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I sign using my Azure IdP, and can see in my Shib SP's shibd.log a session index in the AuthnStatement and later 'new session created'.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
When I go to myapps.microsoft.com and logout, I see the browser's GET request to the Shib SP's ...../SLO/Redirect containing the LogoutRequest, which has a nameId and matching session index matching the login.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
But the request gets rejected and there is a LogoutResponse towards the IdP containing "RequestDenied". <span style="background-color:rgb(255, 255, 255);display:inline !important">The result is that the corresponding SP session that was created earlier does
 not get cleared.</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Has anyone else experienced this? When I use ADFS as IdP, SLO works fine and logs that the SP session is being cleared. (ADFS sends the login assertion encrypted but otherwise the message exchange is similiar).</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
What incoming data mismatches can cause 'RequestDenied'? I'll maybe have to look at the SP source code if I can't enable further trace detail. The logoutrequest message validates on the SAML tools site so it seems the devil is in the detail.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<title>Untitled Document</title>
<div align="center">
<hr size="2" width="100%" align="center">
</div>
<p style="font-family: Arial, Helvetica Neue, Helvetica, sans-serif; font-size: 8pt;margin:0;">
Founded in 1821, Heriot-Watt is a leader in ideas and solutions. With campuses and students across the entire globe we span the world, delivering innovation and educational excellence in business, engineering, design and the physical, social and life sciences.
 This email is generated from the Heriot-Watt University Group, which includes:</p>
<ol style="margin:0;">
<li style="font-family: Arial, Helvetica Neue, Helvetica, sans-serif; font-size: 8pt;">
Heriot-Watt University, a Scottish charity registered under number SC000278</li><li style="font-family: Arial, Helvetica Neue, Helvetica, sans-serif; font-size: 8pt;">
Heriot- Watt Services Limited (Oriam), Scotland's national performance centre for sport. Heriot-Watt Services Limited is a private limited company registered is Scotland with registered number SC271030 and registered office at Research & Enterprise Services
 Heriot-Watt University, Riccarton, Edinburgh, EH14 4AS.</li></ol>
<p style="font-family: Arial, Helvetica Neue, Helvetica, sans-serif; font-size: 8pt;margin:0;">
The contents (including any attachments) are confidential. If you are not the intended recipient of this e-mail, any disclosure, copying, distribution or use of its contents is strictly prohibited, and you should please notify the sender immediately and then
 delete it (including any attachments) from your system.</p>
</body>
</html>