<div dir="ltr">Thanks Scott. makes sense.  <div><br></div><div>If the user does not select local or global logout options, the default is global. Can we change that to be local by default?</div><div><br></div><div>Also, I noticed a mention of <i>idp.logout.propagationHidden</i> in the wiki... I tried to set it to true but does not seem to have hidden the propagation information during logout.</div><div><br></div><div><font face="monospace">idp.logout.propagationHidden=shibboleth.Conditions.TRUE<br></font></div><div><br></div><div><br></div><div>Thanks,</div><div>Mohamed.</div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Mar 6, 2023 at 12:03 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> Is there a way to disable logout propagation in shibboleth IdP?<br>
<br>
Primarily correcting metadata for SPs to indicate a lack of support for it, but also by adjusting the templates to route things directly around that step and  direct it explicitly not to propagate by signaling that choice in the initial view.<br>
<br>
Disabling the logout profile will do it also but with more overhead and it would prevent inbound logout as well.<br>
<br>
I don't personally see why this is a good idea. A few SPs do support logout and they shouldn't be penalized for doing that.<br>
<br>
-- Scott<br>
<br>
<br>
</blockquote></div>