Versions Compared
Key
- This line was added.
- This line was removed.
- Formatting was changed.
This article describes the SAML Single Logout feature in the Smart ID Digital Access component.
SAML Single Logout (SLO) is a SAML flow that allows the end-user to log out from a single session and be automatically logged out of all related sessions that were established during Single Sign-On (SSO).
The end-user can initiate the SLO process from within the Identity Provider (IDP) or one of the Service Providers (SPs). Currently only the front channel SLO works with http-redirect.
Enable Single Logout when Digital Access acts as IDP
Expand | ||
---|---|---|
| ||
|
Expand | ||
---|---|---|
| ||
|
IDP initiated logout flow
Expand | ||
---|---|---|
| ||
Logout flow When the user clicks on logout from Digital Access, acting as IDP with single logout enabled:
Logout status The status of the SP logout, whether it was successful or not, can be seen on the logout page. Issues If there is an issue in any of the SPs to logout, close all the browser windows to make sure there is no dangling session. |
SP initiated logout flow
Expand | ||
---|---|---|
| ||
Logout flow When any participating SP initiates SLO with Digital Access as IDP:
Issues
|
Other
Expand | ||
---|---|---|
| ||
For branding customizations, modify the _slologoutPage.html and _sloResultsPage.html pages. |
Expand | ||
---|---|---|
| ||
|
Expand | ||
---|---|---|
| ||
|
This article is valid for Smart ID 21.10 and later and Digital Access 6.1.0 and later.