Hi. I am trying to get SLO working between WSO2 5.10.0 and NAM 5.0.1. We have SSO working. We have the session on WSO2 being logged out. But, the session on NAM remains. Looking at catalina.out on NAM, I see:

<amLogEntry> 2022-03-18T04:19:48Z INFO NIDS IDFF: AM#500106006: AMDEVICEID#67F5A08EE411D0FA:
Validation failure on message from wso2/NetIQAccessManagerTestIdP : Signature validation failed </amLogEntry>

We are signing logout requests:

Any ideas where we can look? Does the above error mean SLO failed?

I've looked at the SAML trace output between WSO2 and SimpleSAMLphp. From WSO2, I see:


<samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder" />


From SimpleSAMLphp, I see:


<samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" />