<div dir="ltr">IdP 3.4.6<br><br>Hi- I am trying to set up SSO with genetec and they say I must have SingleLogoutService in my metadata. We do not have that explicitly stated in our IdP metadata, we never have. See below. This company uses third party authentication services and does not play well with generic SAML 2.0 so it is difficult to troubleshoot.<br><br>"The url you connect to the webclient isn’t reflective of the uri we present. The construction of the saml request is done at the Directory server level, and the user gets redirected through our own proxy.<br><br>Definitely the redirect uri’s are correct. Right now the failure is happening at our software, when we proxy the request. This indicates that a requirement hasn’t been filled.<br><br>In this case the software is expecting for there to be a SingleLogoutService binding to be available in the metadata. Below is an example from an okta saml config I’ve used in the pas<br><br><md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://dev-47053337.okta.com/app/dev-47053337_securitycenterokta_1/exk29ooutn7iuBXBu5d7/slo/saml">https://dev-47053337.okta.com/app/dev-47053337_securitycenterokta_1/exk29ooutn7iuBXBu5d7/slo/saml</a>"/><br><br><md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://dev-47053337.okta.com/app/dev-47053337_securitycenterokta_1/exk29ooutn7iuBXBu5d7/slo/saml">https://dev-47053337.okta.com/app/dev-47053337_securitycenterokta_1/exk29ooutn7iuBXBu5d7/slo/saml</a>"/>"<div><br></div><div><br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div>Scott Gilbert</div><div>IAM/Cloud System Administrator</div><div>Enterprise Technology Services</div><div>University of California Santa Barbara</div><div><br></div></div></div></div></div></div></div></div></div>