Forum Discussion
APM SP connections - Subject Types
- Jul 19, 2016
If I understand you right, I think you might be under misconception about how SAML IDP configuration works on the BIG-IP. You can certainly have multiple IDP/SP bindings configured on the same virtual server. To fully visualize how it happens, I suggest you leverage this iApp to setup your initial federation with a couple of SaaS apps and take a look at the config it creates - should hopefully be self-explanatory after that. :) If not, fire away your questions here.
https://devcentral.f5.com/codeshare/saas-federation-iapp
If I understand you right, I think you might be under misconception about how SAML IDP configuration works on the BIG-IP. You can certainly have multiple IDP/SP bindings configured on the same virtual server. To fully visualize how it happens, I suggest you leverage this iApp to setup your initial federation with a couple of SaaS apps and take a look at the config it creates - should hopefully be self-explanatory after that. :) If not, fire away your questions here.
https://devcentral.f5.com/codeshare/saas-federation-iapp
I hope things will be self-explanatory once you see the config produced by the iApp. The gist is that you do not have to assign the IDP service to Access Profile as the SSO, but rather as SAML Resource in the VPE, and you can have multiple IDP-to-SP mappings assigned there.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com