在ASP.NET MVC中基于Sustainsys.Saml2实现单点注销(SLO)
在ASP.NET MVC中基于Sustainsys.Saml2.Owin实现Salesforce SAML单点注销(SLO)
你的SSO已正常运行,要实现用户退出应用时同时注销Salesforce会话,需完成以下核心步骤:配置Salesforce IdP端的SLO设置、调整Sustainsys.Saml2的服务提供商(SP)配置、实现应用内注销逻辑。
1. Salesforce端SLO配置
登录Salesforce后台,进入Setup > Apps > App Manager,找到你的SAML应用并点击「Edit」:
- 在「Single Sign-On Settings」区域,勾选Enable Single Logout
- 设置「Single Logout URL」为你的应用的SAML注销端点,默认是
https://你的应用域名/Saml2/Logout - 「Issuer」填写你的SP EntityId(需和Startup里配置的完全一致)
- 若需验证SLO响应,上传你的SP签名证书到「Certificate」字段
2. 修改Sustainsys.Saml2的Startup配置
调整CreateSaml2Options方法,添加SP注销配置和签名证书(Salesforce要求SLO请求必须签名):
public class Startup { public void Configuration(IAppBuilder app) { app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType); app.UseCookieAuthentication(new CookieAuthenticationOptions { AuthenticationType = "Saml2", CookieManager = new Microsoft.Owin.Host.SystemWeb.SystemWebChunkingCookieManager(), SlidingExpiration = true, ExpireTimeSpan = TimeSpan.FromMinutes(Convert.ToDouble(ConfigurationManager.AppSettings["sessionTime"].ToString())) }); app.UseSaml2Authentication(CreateSaml2Options()); } private Saml2AuthenticationOptions CreateSaml2Options() { var saml2Options = new Saml2AuthenticationOptions(false) { SPOptions = new SPOptions { EntityId = new EntityId(ConfigurationManager.AppSettings["EntityId"].ToString()), ReturnUrl = new Uri(ConfigurationManager.AppSettings["ReturnUrl"].ToString()), // 配置SP注销后的回调地址(SLO完成后跳转) LogoutUrl = new Uri("https://你的应用域名/Account/LogoutCallback"), // 配置签名证书,用于签署SLO请求 SigningCertificate = LoadSigningCertificate() }, }; var idp = new IdentityProvider( new EntityId(ConfigurationManager.AppSettings["IssuerUrl"].ToString()), saml2Options.SPOptions) { LoadMetadata = true, SingleSignOnServiceUrl = new Uri(ConfigurationManager.AppSettings["SingleSignOnServiceUrl"].ToString()), MetadataLocation = ConfigurationManager.AppSettings["MetadataLocation"].ToString(), AllowUnsolicitedAuthnResponse = true, // 如果元数据未自动加载Salesforce的SLO地址,可手动指定 // SingleLogoutServiceUrl = new Uri("https://login.salesforce.com/services/oauth2/saml2/logout") }; saml2Options.IdentityProviders.Add(idp); saml2Options.AuthenticationType = "Saml2"; return saml2Options; } // 加载签名证书的辅助方法(示例从本地文件加载) private X509Certificate2 LoadSigningCertificate() { var certPath = HostingEnvironment.MapPath("~/App_Data/YourSPCert.pfx"); return new X509Certificate2(certPath, "你的证书密码"); } }
3. 实现应用内的注销控制器逻辑
在AccountController中添加注销动作,先清除本地认证Cookie,再发起SAML SLO请求到Salesforce:
public class AccountController : Controller { public ActionResult Logout() { // 清除本地SAML认证Cookie var authManager = Request.GetOwinContext().Authentication; authManager.SignOut("Saml2"); // 发起SAML单点注销请求,自动跳转到Salesforce注销页面 return new Saml2LogoutResult(); } // SLO完成后的回调动作,可自定义跳转逻辑 public ActionResult LogoutCallback() { return RedirectToAction("Index", "Home"); } }
关键注意事项
- 确保Salesforce的SAML应用配置中的Entity ID和你SP的
EntityId完全一致 - 签名证书必须是Salesforce信任的证书:若使用自签名证书,需将证书公钥导入Salesforce的Setup > Security > Certificate and Key Management
- 测试时,访问你的应用的
/Account/Logout地址,会先清除本地会话,再跳转到Salesforce完成注销,最后返回你的LogoutCallback页面
内容的提问来源于stack exchange,提问作者Shahab khan
相关产品推荐
相关产品推荐

