Bug 51191 - Add Single Logout to UMC as SAML service provider
Add Single Logout to UMC as SAML service provider
Status: NEW
Product: UCS
Classification: Unclassified
Component: SAML
UCS 4.4
Other Windows NT
: P5 normal (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-04-30 09:52 CEST by Michael Grandjean
Modified: 2021-02-11 20:30 CET (History)
3 users (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 4: Minor Usability: Impairs usability in secondary scenarios
Who will be affected by this bug?: 4: Will affect most installed domains
How will those affected feel about the bug?: 2: A Pain – users won’t like this once they notice it
User Pain: 0.183
Enterprise Customer affected?:
School Customer affected?: Yes
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Grandjean univentionstaff 2020-04-30 09:52:34 CEST
# univention-app info
UCS: 4.4-4 errata548
Installed: nagios=4.3 samba4=4.10 ucsschool=4.4 v5 4.1/nextcloud=18.0.3-0
Upgradable:

Currently, the UMC of all UCS systems of the domain is automatically configured as SAML service provider. Unfortunately, we don't enable Single Logout - the corresponding URL is simply missing at the service provider LDAP object.

This leads to the following behaviour:
a) I open the portal on the UCS Master and login via SAML
b) I also open the UMC of a site server - let's say I'm a teacher and want to use the computer room module on a UCS@school schoolserver. Because the UMC of this schoolserver is a configured SAML service provider, I am automatically logged in
c) I finish my tasks an logoff at the UCS Master
d) I am still logged in on the schoolserver

Imho we should add the Single-Logout URL to the UMC via the corresponding join script.
Comment 1 Michael Grandjean univentionstaff 2021-02-11 17:58:29 CET
This is a requirement in a current tender