Forum Discussion
Lohit
Nimbostratus
May 15, 2025F5 configured SP initiated SAML Authentication causing multiple Redirects
F5 configured (source-ip based) to talk to 2 IBM HTTP Servers and webservers are loadbalancing using Traditional loadbalancing (Round-Robin) and routing requests to 8 JVMs of a Websphere ND Cluster....
Lohit
Nimbostratus
May 16, 2025- The client accesses a protected business application without first authenticating to the IdP or to the application server.
- The application server intercepts the request based on configured filter definitions.
- The application server stores the value of the original request URL on a cookie called WasSamlSpReqUrl.
- The application server redirects the client to the IdP login page that is configured on the sso_<id>.sp.login.error.page custom property.
- Authentication continues following the IdP-initiated SSO flow.
- The user authenticates to the IdP.
- The IdP redirects the client to the Assertion Consumer Service (ACS) (https://abc.com/samlsps/acs) on the WebSphere Application Server by sending a SAML response over HTTP POST.
- The application server processes the SAML response and creates a security context.
- The application server adds an LTPA cookie to the HTTP response.
- The application server uses the value of the WasSamlSpReqUrl cookie to redirect the client to the original request URL. (https://abc.com/maximo)
- Injeyan_KostasMay 16, 2025
Nacreous
ok but what does /maximo expects to let you in?
the LTPA cookie?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects