--- loncom/html/adm/help/tex/Institutional_Integration_Shibboleth.tex 2015/03/26 16:03:55 1.3 +++ loncom/html/adm/help/tex/Institutional_Integration_Shibboleth.tex 2015/03/26 22:15:20 1.4 @@ -255,8 +255,8 @@ Add a file to your Apache conf directory is domain, to include items such as: \begin{verbatim} -PerlSetVar lonSSOUserLogoutHeadFile_/home/httpd/html/adm/sso_logout_head_frag -PerlSetVar lonSSOUserLogoutMessageFile_ /home/httpd/html/adm/sso_logout_body_frag +PerlSetVar lonSSOUserLogoutHeadFile_/home/httpd/html/adm/sso_logout_head +PerlSetVar lonSSOUserLogoutMessageFile_ /home/httpd/html/adm/sso_logout_body PerlSetVar lonSSOUserUnknownRedirect /adm/sso_failed_login.html PerlSetVar lonSSOUserDomain \end{verbatim} @@ -266,9 +266,9 @@ and add the corresponding files owned by Notes: \begin{enumerate} \item -All files will contain HTML mark-up, but the sso\_logout\_head\_frag item is a fragment +All files will contain HTML mark-up, but the sso\_logout\_head item is a fragment inserted into the head block of the standard LON-CAPA logout page, and similarly, -the sso\_logout\_body\_frag is a fragment inserted into the body of the page, +the sso\_logout\_body is a fragment inserted into the body of the page, whereas the sso\_failed\_login.html file should be a complete HTML document. If the name of the PerlVar ends \_$<$dom$>$ then the HTML fragment is only displayed @@ -292,7 +292,7 @@ In pre-2.4 Shibboleth2 /etc/shibboleth2. e.g., https://yourserver/Shibboleth.sso/Logout. Depending on the availability of SLO support from your institution's IdP you should craft an appropriate -message to include in sso\_logout\_link\_html\_frag. If you include a link to the URL for a local logout, +message to include in sso\_logout\_body. If you include a link to the URL for a local logout, you should indicate that access to other web applications using SSO may continue to be available, even after logout from the specific SP. If no local logout is provided, then after logout from LON-CAPA, the web browser needs to be quit, to ensure access to LON-CAPA requires re-authentication. @@ -313,7 +313,7 @@ instead it can come from a customized ge \end{enumerate} -e.g., sso\_logout\_link\_html\_frag +e.g., sso\_logout\_body \begin{verbatim}