-
-
Notifications
You must be signed in to change notification settings - Fork 2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SAML SLS Logout not working, signature validation failed #2132
Comments
I'm experiencing the same issue, which IDP are you using? I'm using Azure AD and when investigating the SAML logout response and attempting to validate it using https://www.samltool.com/validate_logout_res.php I get the same error message, so it appears that (at least in my case) the IDP is to blame because it's incorrectly signing the response. I could be wrong about that though, happy to be corrected. |
@babington-andy I am using a wordpess plugin as IdP - which works great with other SPs. Just the logout flow with bookstack is giving this error. I how no solution until now.. |
I am receiving the same Error message using Azure AD as my idP. Been trying to solve it without any success. |
Also experiencing this. Eventually the authentication session expires on Bookstack but its concerning that the Logout button does not actually log you out of Bookstack with SAML enabled. |
I expierenced the same problem, but also found a way to fix this. Please take a look here: [snip] If you are using the Onelogin PHP Toolkit, then you also have to enable the 'retrieveParametersFromServer'-Setting, otherwise the logout response will always end up with a 'Signature validation failed. Logout Request rejected' error. So the solution is to change the third parameter from false to true in the $toolkit->processSLO function in class BookStack\Auth\Access\Saml2Service:
Eventually this will lead to the function OneLogin\Saml2\Utils::validateBinarySign being called with the 4th parameter $retrieveParametersFromServer to be true instead of false. So in case of Azure, this needs to be truthy and fetched from $_SERVER['QUERY_STRING']. I just tested it and it works like a charm! |
I can not confirm that. I'm also using Azure and had experienced the logout error from the title. When I switch that parameter from false to true I just get an Azure Error instead of that bookstack error (and I'm still logged in). AADSTS50068: Signout failed. The initiating application is not a participant in the current session. |
As per #2902, and issue #1925, a range of changes have now been made for BookStack v21.10. The new Will therefore close this off but please open a new issue if there are problems with the updated implementation. |
Describe the bug
SAML Login workflow is working fine with configuration. However, SLS logout service failes on the bookstack SP with error message
"Invalid SLS Response: invalid_logout_response" with text
"Signature validation failed. Logout Response rejected."
The logout workflow works on the IdP as the user is logged out in the primary IdP environment. However, the HTTP-redirect binding for SO by bookstack delivers the error above. As result, the user is never logged out from bookstack, while correctly logged out at the other app by the IdP.
What is missing here? It looks like a missing signature which need to be set somewhere? But I cant see any additional options to configure the SAML processing via the env file. Is this related to the issue reported #1926 ?
Expected behavior
User should be logged out of the bookstack instance via the SAML SLS HTTP-redirect. As login is working and as the logout is processed correctly by the IdM provider app.
Additional context
#1926
The text was updated successfully, but these errors were encountered: