Skip to main content

Hi. Wondering if some of the Tableau Server Admins out there could check something for me if you use SAML.

 

We're implementing the SAML Logout functionality in v9.1.2, and when we're exporting the service provider metadata from Tableau Server, it's not exporting the binding for SingleLogoutService. According to the SAML Requirements This should be exported so that we can import this metadata into the IdP and then the endpoints will be confirgured. This is how it works for the AssertionConsumerService binding which is included when the xml metadata is exported.

 

I have manually edited the logout endpoint on the IdP, using the info mentioned on the SAML Requirements page and this works ok. My issue is if we then have to re-export our metadata from tableau server to import it into the IdP, we have this manual step to further update the IdP.

 

Can anyone who has 9.1 (or better yet, 9.1.2) and uses SAML, please export the metadata from Tableau Server and see if the line <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="http(s)://<tableauserver>/wg/saml/SingleLogout/index.html"/> appears in it?

 

We have added the tableau saml logout redirect tabadmin set option so I don't think this would be causing this.

 

Tableau don't seem to think this is an issue, I'm just wanting to find out if this is a bug in the software, or an issue with our setup.

 

Thanks

 

Graham

4 answers
  1. Jan 1, 2016, 1:42 AM

    Can you please direct me where to add the missing md element? The export metadata file did not have the SingleLogoutService element. My questions is what should be added to the SAML idp metadata xml file and is there is anything else that needed to be added elsewhere? Scrubbed examples would be great.

0/9000