Forum Discussion

PABLO_MORENO_GO's avatar
PABLO_MORENO_GO
Icon for Nimbostratus rankNimbostratus
Jun 01, 2018

Problems with SLO in APM SAML when 2 or more SP are loged in and try to logout

I have the following problem with the module APM, specifically with the functionality of SAML as IDP, the situation is the following, at the moment that 2 or more SP that are authenticated against the IDP and work without problems, try to perform an SLO (Single Logout) from any of the SP, an error is generated at the level of the module APM which prevents that the logout action is achieved.

 

The sequence of actions is as follows

 

1.- Login request from the first SP 2.- first SP authenticates in IDP with success 3.- Login request from second SP 4.- Second SP is authenticated in IDP with success 5.- Logout requested from the first SP 6.- IDP sends request of logout to the second SP 7.- Logout of the second SP fails with the following error

 

Jun 1 13:55:08 f504dmz debug tmm [19281]: 014d0002: 7: 402257c8: SSOv2 XPATH_SLO_NAMEID_FORMAT: (51) urn: oasis: names: tc: SAML: 2.0: nameid-format: transient Jun 1 13:55:08 f504dmz debug tmm [19281]: 014d0002: 7: 402257c8: SSOv2 XPATH_SLO_NAMEID: (17) analistarm1-1-1-1

 

The following connection "/ sec / SP_Sparta_v2" exists Jun 1 13:55:08 f504dmz err tmm [19281]: 014d0002: 3: 402257c8: SSOv2 Failed to find SP connector in SAML SLO data: '/ sec / SP_Sparta_v2: _e4740073cc3b68549761548bc625058b046857: / sec / uaa_latam_idp: YW5hbGlzdGFybTEtMS0xLTE ='

 

Jun 1 13:55:08 f504dmz err tmm [19281]: 014d0002: 3: 402257c8: SSOv2 Check SLO configuration on SP 'https://uaa.svc.lan.com/saml/idp' Jun 1 13:55:08 f504dmz err tmm [19281]: 014d0002: 3: 402257c8: SSOv2 Error (12) processing SLO request

 

Basically what the IDP does here is send a request of logout to the SP that are active, but something happens that the IDP is not able to find the connectors of said SP, which fails the logout

 

Please CON ANYONE HELP ME!!!, since i cannot logout several SPs, logout each SP separately if possible and work correctly, but when there is more than one SP, no.

 

No RepliesBe the first to reply