Forum Discussion
Ingebrigt_Maurs
Nimbostratus
May 04, 2015APM doesn't use RelayState value sent in Request
I have trouble making RelayState work. I use APM as an IDP-initiated SP. I send RelayState with the assertion. The spec for sending RelayState to APM as a SP is unclear/absent, so I send it in the sa...
Ingebrigt_Maurs
Nimbostratus
May 04, 2015Also, if I set a default RealyState on the SP, this will break SP-initiated SSO.
I set default RelayState on the SP to
https://myhost.no/default/path
As a client, I go to
https://myhost.no/intended/path.
As expected I get redirected to the IDP, authenticate, and then I am redirected back to the SP ACS with RelayState
https://myhost.no/intended/path. But unfortunately I am sent to https://myhost.no/default/path. Correct behaviour would have been to be sent to my intended url https://myhost.no/intended/path.- Michael_Koyfma1May 04, 2015
Cirrus
Ok, I am a little bit confused here, so need to clarify. Are you saying that APM is IDP and you are having issues with this config? If so, what is your SP? Is your goal to support both IDP and SP-initiated logons? The reason for my confusion is you continue to cite documentation about APM acting as SP and how it handles RelayState parameter - but to me, it sounds like you are using APM as an IDP - and that documentation portion does not apply then. - Ingebrigt_MaursMay 05, 2015
Nimbostratus
I use APM as SP. My goal is to support both IDP and SP initiated logons. It is IDP initiated that is causing me trouble. BUT, SP initiated is also acting strange if I set a the 'RelayState' property of the SP configuration. If I as a client go to https://sp.no/intended/path I expected to end up there after SSO. But actually I end up at the URL specified by the RelayState property on the SP, if this is set. I'm unsure if this is a bug or a feature, but it certainly means I can't use the RelayState property. Because all clients using SP-initiated SSO will land on the URI specified in the RelayState property (and not on the landinguri they tried to reach).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects