<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p>Hi again,</p>
<p>forgot to include what keycloak is saying if it gives any hints:<br>
</p>
<p>024-03-17 13:13:50,815 ERROR
[org.keycloak.services.error.KeycloakErrorHandler]
(executor-thread-10) Uncaught server error:
java.lang.ClassCastException: class
org.keycloak.dom.saml.v2.protocol.StatusResponseType cannot be
cast to class
org.keycloak.dom.saml.v2.protocol.RequestAbstractType
(org.keycloak.dom.saml.v2.protocol.StatusResponseType and
org.keycloak.dom.saml.v2.protocol.RequestAbstractType are in
unnamed module of loader
io.quarkus.bootstrap.runner.RunnerClassLoader <span
class="mention">@3c679bde</span>)</p>
<p>Cheers,</p>
<p>Tomas<br>
</p>
<div class="moz-cite-prefix">On 2024-03-17 14:43, Tomas Stenlund via
users wrote:<br>
</div>
<blockquote type="cite"
cite="mid:ef0cb9d0-bf2e-4dfe-989f-412c7e370254@telia.com">Hi,
<br>
<br>
I have been using Keycloak 23.0.7 with Shibboleth IdP 5.0.0 as an
IdP broker and it works perfectly fine both login and logout
flows.
<br>
<br>
But when I upgraded to the latest Shibboleth 5.1.0 the logout flow
broke with keycloak returning a 500 when it got the LogoutResponse
with the statuscode urn:oasis:names:tc:SAML:2.0:status:Success.
There is no visible difference between the 5.0.0 and 5.1.0 Shib
messages from what I can see but obviously there is something that
differ.
<br>
<br>
I just wanted to know if there has been any changes from 5.0.0 to
5.1.0 that would affect the logout flow on the Shib-side? I am
currently increasing logs in keycloak now to see if I can spot
anything that points me in the right direction.
<br>
<br>
Thanks a lot,
<br>
<br>
Tomas
<br>
<br>
</blockquote>
</body>
</html>