Forum Discussion
SSO logout process with f5
We are using a salesforce application that uses f5 as SSO IDP. Every time a user logs out it gets the next error messsage from https://hsc-idp-camino.health.unm.edu/saml/idp/profile/post/sls
The requested file was not found on the server. Please contact system administrator!
Question 1: How can we do to change the content of this message?
Question 2: We might like to redirect to another webpage instead of showing this message. How can this be done?
Thanks in advance Jose C. Cabrera Zuniga
8 Replies
- Yann_Desmarest_
Nacreous
Hi,
Looks like, The Single Logout is missing on your idp.
Did you configure it in your IDP profile on F5 ?
- JOSECCZ_261067
Nimbostratus
SLO is configured on the IdP but it may not be configured correctly. The configuration that is in place on the IdP… SLO Request URL: blank SLO Response URL: https://hsc-idp-camino.health.unm.edu/saml/idp/profile/post/slr …is able to end the sessions both in the F5 and in SF when the user logs out of SF. However, it also results in the error that you are seeing. The information in the SF Single Sign-On Implementation Guide (Winter '16), "Start, Login, and Logout URL Values" and "Customize SAML Start, Error, Login, and Logout Pages" sections are not clear as to how to configure the Identity Provider Logout URL and the Custom Error URL fields in the SF SAML SSO Settings configuration page Can you please give us more details about how to do this configuration? Thanks - Yann_Desmarest_
Nacreous
The following is the url of the SLO request : https://hsc-idp-camino.health.unm.edu/saml/idp/profile/post/sls - Yann_Desmarest_
Nacreous
Are you sure that you are using the same binding method on both SP and IDP : POST or REDIRECT ?
Hi,
Looks like, The Single Logout is missing on your idp.
Did you configure it in your IDP profile on F5 ?
- JOSECCZ_261067
Nimbostratus
SLO is configured on the IdP but it may not be configured correctly. The configuration that is in place on the IdP… SLO Request URL: blank SLO Response URL: https://hsc-idp-camino.health.unm.edu/saml/idp/profile/post/slr …is able to end the sessions both in the F5 and in SF when the user logs out of SF. However, it also results in the error that you are seeing. The information in the SF Single Sign-On Implementation Guide (Winter '16), "Start, Login, and Logout URL Values" and "Customize SAML Start, Error, Login, and Logout Pages" sections are not clear as to how to configure the Identity Provider Logout URL and the Custom Error URL fields in the SF SAML SSO Settings configuration page Can you please give us more details about how to do this configuration? Thanks - The following is the url of the SLO request : https://hsc-idp-camino.health.unm.edu/saml/idp/profile/post/sls
- Are you sure that you are using the same binding method on both SP and IDP : POST or REDIRECT ?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com