<div dir="ltr"><div dir="ltr"><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Jan 19, 2022 at 4:01 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 1/19/22, 3:30 PM, "Michael Grady" <<a href="mailto:mgrady@unicon.net" target="_blank">mgrady@unicon.net</a>> wrote:<br>
<br>
>    And if you are not trying to propagate logout anyways, another option might be you simply do not have the<br>
> Shib IdP keep a session in the first place, and list an Azure AD logout endpoint that does not require a SAML<br>
> logout message (just like the Shib IdP's profile/Logout endpoint) as the logout endpoint when you configure<br>
> the SP with the Shib IdP. (Assuming Azure AD has such a logout endpoint.)</blockquote><div><br></div><div>I had not considered dropping Shib IDP session creation as a whole. That seems like a pretty elegant solution to the problem.  Is configuring for that as straightforward as setting ip.session.enabled=false in idp.properties, or is there anything else that'd need to be done?</div><div><br></div><div>I remembered looking at a meta refresh redirect to Azure, but found that the url that Azure SSO uses is indeed SAML-based(<a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-out-saml-protocol">https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-out-saml-protocol</a>).  Does that make this sort of logout a feature request or is there some way to craft and send the samlp:LogoutRequest in the template?</div><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
Whenever you're dealing with something not in the metadata, you have something "unmanaged", and that should never be directly pointing to a piece of software you don't control (as in, the IdP could change that URL for some reason, but a script you own lives where you decide it does).<br>
<br>
I use /cgi-bin/logout.cgi on my IdP servers for that, and I never allow direct references to /idp/profile/Logout.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div dir="ltr">Jeffrey Williams </div><div dir="ltr">Identity & Access Engineer<br>Identity & Access Services<br><a href="https://its.uncg.edu" target="_blank">https://its.uncg.edu</a></div></div><div dir="ltr"><br></div><div dir="ltr"><img src="https://uncgcdn.blob.core.windows.net/email/UNCGLogo.png"><br></div></div></div></div></div></div></div></div></div></div>