Forum Discussion
Add Subject element to the AuthnRequest
I need to configure the BIG-IP as a SP and need to add a Subject element to the AuthnRequest. I can't figure out where to configure this. I'm trying to add something like the following to the SAML request:
urn:collab:person:some-organisation.example.org:m1234567890
Hope someone can point me in the right direction.
Best regards,
Niels
3 Replies
Niels,
Isn't this configured under advanced setting (SMAL SP service) and then from the dropdown menu (Name-Identifier Policy Format)??? There you can select urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified In the SP Name-Identifier Qualifier you can construct your answer from sessions variables of fixed values.
Cheers,
Kees
No, these are not the same. The 'SPNameQualifier' is part of the 'Issuer' element and relates to the 'Entity ID'.
Currently it isn't possible to add a Subject element to the AuthnRequest through the Config Utility or tmsh. But with iRulesLX I managed to add the Subject element to the original SAMLRequest that the BIG-IP produces. Use the link below to get the code.
https://devcentral.f5.com/codeshare/surfconext-second-factor-only-sfo-authentication-1012
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com