1
0
mirror of synced 2026-08-04 17:27:13 +00:00

Add SAML 2.0 Single Logout XML Support

Closes gh-10842
This commit is contained in:
Marcus Da Coregio
2022-02-17 15:52:41 -03:00
committed by Marcus Hert Da Coregio
parent 73f839312d
commit 93d4fd3559
18 changed files with 1336 additions and 6 deletions
@@ -165,6 +165,7 @@ The default value is true.
* <<nsa-remember-me,remember-me>>
* <<nsa-request-cache,request-cache>>
* <<nsa-saml2-login,saml2-login>>
* <<nsa-saml2-logout,saml2-logout>>
* <<nsa-session-management,session-management>>
* <<nsa-x509,x509>>
@@ -1342,11 +1343,78 @@ The AssertionConsumerService Location. Equivalent to the value found in `&lt;Ass
the AssertionConsumerService Binding. Equivalent to the value found in `&lt;AssertionConsumerService Binding="..."/&gt;` in the relying party's `&lt;SPSSODescriptor&gt;`.
The supported values are *POST* and *REDIRECT*.
[[nsa-relying-party-registration-single-logout-service-location]]
* **single-logout-service-location**
The SingleLogoutService Location. Equivalent to the value found in &lt;SingleLogoutService Location="..."/&gt; in the relying party's &lt;SPSSODescriptor&gt;.
[[nsa-relying-party-registration-single-logout-service-response-location]]
* **single-logout-service-response-location**
The SingleLogoutService ResponseLocation. Equivalent to the value found in &lt;SingleLogoutService ResponseLocation="..."/&gt; in the relying party's &lt;SPSSODescriptor&gt;.
[[nsa-relying-party-registration-single-logout-service-binding]]
* **single-logout-service-binding**
The SingleLogoutService Binding. Equivalent to the value found in &lt;SingleLogoutService Binding="..."/&gt; in the relying party's &lt;SPSSODescriptor&gt;.
The supported values are *POST* and *REDIRECT*.
[[nsa-relying-party-registration-asserting-party-id]]
* **asserting-party-id**
A reference to the associated asserting party. Must reference an `<asserting-party>` element.
[[nsa-relying-party-registration-children]]
=== Child Elements of <relying-party-registration>
* <<nsa-decryption-credential,decryption-credential>>
* <<nsa-signing-credential,signing-credential>>
[[nsa-decryption-credential]]
== <decryption-credential>
The decryption credentials associated with the relying party.
[[nsa-decryption-credential-parents]]
=== Parent Elements of <decryption-credential>
* <<nsa-relying-party-registration,relying-party-registration>>
[[nsa-decryption-credential-attributes]]
=== <decryption-credential> Attributes
[[nsa-decryption-credential-certificate-location]]
* **certificate-location**
The location to get the certificate
[[nsa-decryption-credential-private-key-location]]
* **private-key-location**
The location to get the Relying Party's private key
[[nsa-signing-credential]]
== <signing-credential>
The signing credentials associated with the relying party.
[[nsa-signing-credential-parents]]
=== Parent Elements of <verification-credential>
* <<nsa-relying-party-registration,relying-party-registration>>
[[nsa-signing-credential-attributes]]
=== <verification-credential> Attributes
[[nsa-signing-credential-certificate-location]]
* **certificate-location**
The location to get this certificate
[[nsa-signing-credential-private-key-location]]
* **private-key-location**
The location to get the Relying Party's private key
[[nsa-asserting-party]]
== <asserting-party>
@@ -1394,6 +1462,22 @@ The supported values are *POST* and *REDIRECT*.
The list of `org.opensaml.saml.ext.saml2alg.SigningMethod` Algorithms for this asserting party, in preference order.
[[nsa-asserting-party-single-logout-service-location]]
* **single-logout-service-location**
The SingleLogoutService Location. Equivalent to the value found in &lt;SingleLogoutService Location="..."/&gt; in the asserting party's &lt;IDPSSODescriptor&gt;.
[[nsa-asserting-party-single-logout-service-response-location]]
* **single-logout-service-response-location**
The SingleLogoutService ResponseLocation. Equivalent to the value found in &lt;SingleLogoutService ResponseLocation="..."/&gt; in the asserting party's &lt;IDPSSODescriptor&gt;.
[[nsa-asserting-party-single-logout-service-binding]]
* **single-logout-service-binding**
The SingleLogoutService Binding. Equivalent to the value found in &lt;SingleLogoutService Binding="..."/&gt; in the asserting party's &lt;IDPSSODescriptor&gt;.
The supported values are *POST* and *REDIRECT*.
[[nsa-asserting-party-children]]
=== Child Elements of <asserting-party>
@@ -1795,6 +1879,67 @@ Reference to the `AuthenticationFailureHandler`.
Reference to the `AuthenticationManager`.
[[nsa-saml2-logout]]
== <saml2-logout>
The xref:servlet/saml2/logout.adoc#servlet-saml2login-logout[SAML 2.0 Single Logout] feature configures support for RP- and AP-initiated SAML 2.0 Single Logout.
[[nsa-saml2-logout-parents]]
=== Parent Elements of <saml2-logout>
* <<nsa-http,http>>
[[nsa-saml2-logout-attributes]]
=== <saml2-logout> Attributes
[[nsa-saml2-logout-logout-url]]
* **logout-url**
The URL by which the relying or asserting party can trigger logout.
[[nsa-saml2-logout-logout-request-url]]
* **logout-request-url**
The URL by which the asserting party can send a SAML 2.0 Logout Request.
[[nsa-saml2-logout-logout-response-url]]
* **logout-response-url**
The URL by which the asserting party can send a SAML 2.0 Logout Response.
[[nsa-saml2-logout-relying-party-registration-repository-ref]]
* **relying-party-registration-repository-ref**
Reference to the `RelyingPartyRegistrationRepository`.
[[nsa-saml2-logout-logout-request-validator-ref]]
* **logout-request-validator-ref**
Reference to the `Saml2LogoutRequestValidator`.
[[nsa-saml2-logout-logout-request-resolver-ref]]
* **logout-request-resolver-ref**
Reference to the `Saml2LogoutRequestResolver`.
[[nsa-saml2-logout-logout-request-repository-ref]]
* **logout-request-repository-ref**
Reference to the `Saml2LogoutRequestRepository`.
[[nsa-saml2-logout-logout-response-validator-ref]]
* **logout-response-validator-ref**
Reference to the `Saml2LogoutResponseValidator`.
[[nsa-saml2-logout-logout-response-resolver-ref]]
* **logout-response-resolver-ref**
Reference to the `Saml2LogoutResponseResolver`.
[[nsa-attribute-exchange]]
== <attribute-exchange>
The `attribute-exchange` element defines the list of attributes which should be requested from the identity provider.