Forum Discussion
Roman_178798
Nimbostratus
Apr 11, 2016APM is not forwarding authentication token to ADFS
Hello experts,
we configured ADFS on F5, in deployment guide, the name is Securing AD FS with the BIG-IP APM.
Customer had another demmand, to authenticat with UPN only, not with SAMACCOUNTNAME....
Josiah_39459
Apr 11, 2016Historic F5 Account
Since the LDAP auth applies only to the Access Policy, it has no bearing on the backend server. It sounds to me like your problem is likely in the SSO.
You didn't say what type of SSO you are using, but if it is expecting the samaccountname and you are sending the UPN and they are different, it's obviously going to fail, right?
- BigFootApr 11, 2016
Nimbostratus
Yes, I am using NTLMv1, sorry forgot to add here. and setting is default.Just domain is different. According to application team, they cannot see any authentication attemp on ADFS - Josiah_39459Apr 11, 2016Historic F5 AccountWell, a packet capture and websso logs (potentially debug) will tell you for sure. NTLM's just a http header. But it seems as a bare minimum you have to fix your SSO credential assign to be valid.
- BigFootApr 21, 2016
Nimbostratus
It takes some time, but I did packet capture, decrypt traffic, but it seems that user's credentials are not added to the NTLM header, so they are not passed to ADFS. Does anybody know please, how the correct setup should looks like for ADFS with authentication based on UPN and not SamAccountName?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
