Forum Discussion
F5 configured SP initiated SAML Authentication causing multiple Redirects
Thanks for the response.
We have 2 applications deployed in Cluster. (F5 is fronending it)
1. Maximo (https://abc.com/maximo) --- Session management enabled with Cookie (JSESSIONID)
2. WebsphereISP (AcS Assertion with Entra). The assertion URL within websphere security is configured as https://abc.com/samlsps/acs. --- Session management enabled with Cookie (JSESSIONIDSAML)
SAML flow is mentioned as per the below link.
https://www.ibm.com/docs/en/was/9.0.5?topic=sign-saml-single-scenarios-features-limitations
https://www.ibm.com/docs/en/was/9.0.5?topic=swss-enabling-saml-sp-initiated-web-single-sign-sso
The problem what i feel is when we hit LB URL (1) it routes to a particular JVM and then again to initiate Assertion authentication with Entra we are using (2). During this flow i believe , JSESSIONID is lost between Entra and Application.
DO you think your solution should still work in this case?
- May 16, 2025
If JSESSIONID is not included probably not.
If you leave only one Http server available, the same to both pools, does it work?- LohitMay 16, 2025
Nimbostratus
I can enforce JSESSIONID same as both.. But with that as well the problems persisted earlier. If 1 HTTP Server is up and running, The redirect is still happening but response is better compared to previous case.
- May 16, 2025
If you have same issue even with only one http server, then your problem is not persistence
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com