Forum Discussion
bdavis
Nimbostratus
Dec 15, 2015APM SSO Multiple SP's utilizing single IDP - Inactivity Timeout
Any help would be appreciated. Here's the scenario. We have a IDP setup on the F5 that we use for SSO with multiple SP's associated with it. The functionality we are wanting is the user can obviously...
Michael_Koyfma1
Cirrus
Dec 15, 2015I am not sure that scenario is possible. SAML is the standard for authentication - but IDP is not a proxy of user application connections - it merely issues an assertion and sends the user on its merry way to access any given SP. When APM acts as an IDP, user has a session with APM, and that session has its own timeout. SAML as a protocol does not have any mechanism built in, as far as I know, to keep track of user activity and associated timeouts - which is why I am not seeing how the scenario you're seeking is possible to accomplish.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects