<div dir="ltr"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div>In the logs, it doesn't throw any errors. Here is what it shows:</div><div>





<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:11px;line-height:normal;font-family:Menlo;color:rgb(0,0,0)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures">2022-05-16 10:46:09,734 - INFO [Shibboleth-Audit.Logout:283] - 2022-05-16T15:46:09.734566Z||||<a href="http://shibboleth.net/ns/profiles/logout||||sherrera|||||">http://shibboleth.net/ns/profiles/logout||||sherrera|||||</a></span></p>
<p class="gmail-p1" style="margin:0px;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal;font-size:11px;line-height:normal;font-family:Menlo;color:rgb(0,0,0)"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures">2022-05-16 10:46:09,803 - INFO [Shibboleth-Audit.LogoutPropagation:283] - 2022-05-16T15:46:09.803312Z|||<a href="http://google.com/a/REDACTED|http://shibboleth.net/ns/profiles/saml2/logout|https://REDACTED|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_fc7ca430632f77d31c314119f95706b9||||sherrera@REDACTED||">google.com/a/REDACTED|http://shibboleth.net/ns/profiles/saml2/logout|https://REDACTED|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_fc7ca430632f77d31c314119f95706b9||||sherrera@REDACTED||</a></span></p></div></div></div><br><div>How do you recommend killing the session when the user hits logout? If Google doesn't support SAML logout, what options should I pursue? </div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, May 16, 2022 at 7:08 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 5/14/22, 4:44 PM, "Steve Herrera" <<a href="mailto:sherrera@fsmail.bradley.edu" target="_blank">sherrera@fsmail.bradley.edu</a>> wrote:<br>
<br>
>    The reason I thought it would support it is because Google has a config requesting Sign-out Page URL.  I<br>
> pointed that to our IDP Logout page and it redirects it correctly there.<br>
<br>
That's not a SAML logout.<br>
<br>
>    Maybe this is expected behavior for the IDP properly killing the session and I just did not know what to<br>
> expect.  <br>
<br>
Your logs will tell you exactly why it failed, and no, it didn't work.<br>
<br>
-- Scott<br>
<br>
<br>
<br>
</blockquote></div>