Twelve decisions about registration, signatures, authorities, logout and revocation.
Review before answering
- Spring Security SAML relying party: align registration, ACS and metadata
- Spring Security SAML validation: signatures, audience and clock window
- Spring Security SAML logout: local session versus single logout
- Spring SAML session revocation: closing the browser is not deprovisioning
Edge Cases
Choose the outcome that preserves the documented boundary under failure, not just the path that works once.
