Forum Discussion

Marfex's avatar
Marfex
Icon for Nimbostratus rankNimbostratus
Oct 01, 2018

SAML SP Close session after redirect to IDP

Hello all!

 

I have an F5 configured as SP for an external IDP vendor. Under certain VPE conditions (after the client has authenticated with SAML), the user may hit a Redirect Ending with the option "Close session after redirect" selected.

 

In fact, this option close the session on the F5, but do not close it on the IDP. In consecuence, if the user hit the VS again, the SAML session on the IDP is still valid and the login prompt won't show up.

 

Any ideas to close the session on both sides?

 

Thanks!

 

1 Reply

  • Marfex's avatar
    Marfex
    Icon for Nimbostratus rankNimbostratus

    If someone get this issue. The F5 is able to close the session because it saw a logout hit ... even if the IDP do not confirm the logout (independent of POST or Redirect).

     

    In my case, the IDP had a certificate matching problem asertions for logout. After they fix that, everything worked out.