Version Affected: All
Overview
This article explains why there is no option to set a LogoutURL for a SAML realm in the SecureAuth Classic console, when a Service Provider requires one for a full logout.
Cause
The Classic admin console does not include a LogoutURL setting for SAML configurations. The New Experience console does include a LogoutURL setting for SAML configurations.
Resolution:
To resolve this, if the Service Provider allows a custom logout URL to be configured in its own admin console, set it to one of the following SecureAuth appliance URLs, either of which performs a proper logout for the end user:
- https://<realm URL>/restart.aspx — logs the user out and returns them to the realm's login page or start page.
- https://<realm URL>/logout.aspx — logs the user out.
Special Considerations
If the SecureAuth appliance uses Transparent SSO (TSSO), using either URL logs the end user out of the appliance. On the next attempt to use an application, the end user is prompted to authenticate again, as if logging in for the first time.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.