Forum Discussion
Problems with SLO in APM SAML when 2 or more SP are loged in and try to logout
I have the following problem with the module APM, specifically with the functionality of SAML as IDP, the situation is the following, at the moment that 2 or more SP that are authenticated against the IDP and work without problems, try to perform an SLO (Single Logout) from any of the SP, an error is generated at the level of the module APM which prevents that the logout action is achieved.
The sequence of actions is as follows
1.- Login request from the first SP 2.- first SP authenticates in IDP with success 3.- Login request from second SP 4.- Second SP is authenticated in IDP with success 5.- Logout requested from the first SP 6.- IDP sends request of logout to the second SP 7.- Logout of the second SP fails with the following error
Jun 1 13:55:08 f504dmz debug tmm [19281]: 014d0002: 7: 402257c8: SSOv2 XPATH_SLO_NAMEID_FORMAT: (51) urn: oasis: names: tc: SAML: 2.0: nameid-format: transient Jun 1 13:55:08 f504dmz debug tmm [19281]: 014d0002: 7: 402257c8: SSOv2 XPATH_SLO_NAMEID: (17) analistarm1-1-1-1
The following connection "/ sec / SP_Sparta_v2" exists Jun 1 13:55:08 f504dmz err tmm [19281]: 014d0002: 3: 402257c8: SSOv2 Failed to find SP connector in SAML SLO data: '/ sec / SP_Sparta_v2: _e4740073cc3b68549761548bc625058b046857: / sec / uaa_latam_idp: YW5hbGlzdGFybTEtMS0xLTE ='
Jun 1 13:55:08 f504dmz err tmm [19281]: 014d0002: 3: 402257c8: SSOv2 Check SLO configuration on SP 'https://uaa.svc.lan.com/saml/idp' Jun 1 13:55:08 f504dmz err tmm [19281]: 014d0002: 3: 402257c8: SSOv2 Error (12) processing SLO request
Basically what the IDP does here is send a request of logout to the SP that are active, but something happens that the IDP is not able to find the connectors of said SP, which fails the logout
Please CON ANYONE HELP ME!!!, since i cannot logout several SPs, logout each SP separately if possible and work correctly, but when there is more than one SP, no.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com