Forum Discussion
Kevin_Grumball_
Nimbostratus
Oct 22, 2014Examining SAML claims for managing permissions
I'm designing a gateway for some legacy systems which cannot consume SAML. We have an STS which issues SAML tokens to end-user applications and these pass through the enterprise. It's a single STS, w...
Kevin_Grumball_
Nimbostratus
Oct 22, 2014Yes, the SAML token is digitally signed by the STS, which is independent of the F5, or any external HTTPS. If we used ADFS internally for this (and we might) then it would have the same issues. The F5 gateway will have the public key of the STSs, so that it can validate the SAML tokens.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects