(Optional) Enable signed logout requests
Some IdPs require the Service Provider to sign logout requests with a certificate.
Before you begin
Role required: sso_config_admin, business_rule_admin, script_include_admin
About this task
If your IdP requires signed logout requests, use the IdP's metdata to set the following system properties.
Procedure
In the Advanced tab, from the property Sign LogoutRequest. Set this property to true if the Identity Provider's SingleLogoutRequest service requires signed LogoutRequest, select Yes to specify that your IdP requires a signed logout request, or select No to use unsigned logout requests.
If you selected Yes to Sign LogoutRequest, then in The protocol binding for the Identity Provider's SingleLogoutRequest service. (Value can be either "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" or "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST".) property, enter the one of the supported values listed in
Bindingattribute from theSingleLogoutServiceelement.By default, the integration uses an HTTP-Redirect binding.
Click Update.