Forum Discussion

bdavis's avatar
bdavis
Icon for Nimbostratus rankNimbostratus
May 17, 2016

APM: SAML IDP "ACCESS::policy evaluate" and SAML SSO

So I have a VIP that's main purpose is to provide SAML IDP service via APM and respond back to SP's with SAML Responses. I have a need for these SP's to come to the IDP over 4 different URI's to identify what information they require back in the SAML response. So I realize I could setup 4 seperate VIPs to accomplish this and do VIP targeting, but my question would be is there an simpler way? So I know that you can call different APM profiles via irule with "ACCESS::policy evaluate" which would do what I want which is separate the APM flow based off of URI. But what happens to SAML AuthN and SAML Response when the SSO profile is attached to each of the APM profiles that I'm calling in an irule, is SAML SSO profiles even supported when using "ACCESS::policy evaluate"? Any information would be greatly appreciated.

 

2 Replies

  • Hello,

     

    This irule command has been design for non browser apps.

     

    SAML require a browser on the client side to work properly (except for ecp profiles)

     

  • Hello,

     

    This irule command has been design for non browser apps.

     

    SAML require a browser on the client side to work properly (except for ecp profiles)