[keycloak-user] ResponseLocation in SAML identity broker

Leonid Rozenblyum lrozenblyum at gmail.com
Wed Nov 6 02:40:23 EST 2019


Hello!
Does keycloak support ResponseLocation for SAML identity broker for Single
Logout?
(see https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf

*2.2.2 Complex Type EndpointType *
*ResponseLocation *[Optional] Optionally specifies a different location to
which response messages sent as part of the protocol or profile should be
sent. The allowable syntax of this URI depends on the protocol binding.

We need integrating with an IdP that uses *ResponseLocation *different
from *Location
*and rejects our single logout responses.

Is this feature somehow tunable in keycloak?


More information about the keycloak-user mailing list