[keycloak-dev] Issue with single sign out using salesforce SP with keycloak IDP and also customizing the logout page

Rashmi Singh singhrasster at gmail.com
Thu Aug 18 22:06:55 EDT 2016


Hi,

I have setup a Salesforce Saml SP in keycloak. So, I basically created a
new client from keycloak admin console for salesforce. This is how my SP
url looks like:

rashmi789-dev-ed.my.salesforce.com

I edited the salesforce configuration settings to point it to the keycloak
IDP. So, when I access the SP: http://rashmi789-dev-ed.my.salesforce.com

I am successfully taken to the keycloak IDP page (where I have configured
my Authenticator). I enter my credentials there and am able to login. But,
now when I try to logout, I get the following error on the web page:

We're sorry ...
Invalid Request

So, single sign out does not seem to be working for me. What is the issue?
Is it a problem with the IDP logout url that I have configured? What I have
is:

http://rashmiidp.cloud.com:9990/auth/realms/saml-demo/protocol/saml


my IDP Login URL is:
http://rashmiidp.cloud.com:9990/auth/realms/saml-demo/protocol/saml

and that seem to be perfectly fine as I am able to login without any issue.
what is the issue with the logout I am seeing above when using a Salesforce
SP with keycloak? Please let me know if you need me to provide more details.

Also, once this issue is resolved and I am able to logout successfully,
could you give some insights on how to customize the logout page?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.jboss.org/pipermail/keycloak-dev/attachments/20160818/0a4ab6e3/attachment.html 


More information about the keycloak-dev mailing list