<div dir="ltr">Hi<br><br>According to <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631693#Notes">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631693#Notes</a> Responses are not signed if the response is being transmitted over HTTPS to a non 443 port.  At least that's my interpretation.<br><br>I have setup a test SP that logs in successfully via a Shibboleth 4 IdP that I have configured as a test.  The IdP logs in the user via LDAP and saves the session to MySQL.  It then responds with an encrypted Assertion which the SP correctly decrypts and uses..<br><br>If I request Logout via the HTTP-Redirect I get a properly signed Successful LogoutResponse and the session is deleted from the database and the SP works.<br><br>If I request logout via SOAP I get an UNSIGNED successful LogoutResponse and the session is deleted from the database.  Unfortunately my test SP does not like unsigned LogoutResponses.<br><br>Is it possible to configure Shibboleth to sign the SOAP based LogoutResponse?<br><br>Tim<div><br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr">Timothy Legge<div><a href="mailto:timlegge@gmail.com" target="_blank">timlegge@gmail.com</a></div><div><a href="mailto:timlegge@cpan.org" target="_blank">timlegge@cpan.org</a></div></div></div></div></div></div>