Next in thread →
Next in month →
RE: [security-services] SLO processing rules
Ok, I've uploaded core-3c and profiles-3c to correct the inconsistency. Propagation (and in fact the overall logout operation really) is a SHOULD, because that's what it's been in the actual logout processing rules. I just changed the intro text, the new language, and the profile to match it. The gist is that the SP can request logout, but the SA only has to listen, it doesn't have to do it. It has to tell the SP what it did (Success vs failure), but that's it. Of course, it's a SHOULD, meaning not doing it is only intended for SAs with special requirements. -- Scott
Next in thread →
Next in month →