Forum Discussion
rgordon_01
Nimbostratus
Sep 11, 2018Can SAML request issuer and SP connector entity id be different
Here's my problem. Our f5 is acting as idP. When I go to the SP initiated link it does not work. I get a page cannot be displayed. I can see in fiddler it's adding -
?binding=urn:oasis:names:tc:S...
youssef1
Cumulonimbus
Sep 11, 2018Hi,
You have to check 2 things, so it's a good thing that you use Fiddler.
Capture saml request using fiddler then decode the saml request using this link:
https://www.samltool.com/decode.php
Then checked the following point in your saml request (decode):
- saml issuer
It will be your SP entity ID that you set in your external SP
- ACS: saml AssertionConsumerServiceURL
AssertionConsumerServiceURL="It will be ACS URL that you set on your external SP"
if that's not the case you have to change the settings of your external sp on F5, for addapter. Sometimes you retrieve metadata of an external app and app owner change them without provide you the new info...
Hope it's clear. keep me update.
regards
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects