Forum Discussion
F5 APM and Azure Access Control Service
Hi there,
We are considering using F5 APM as an Identity Provider for our Azure ASP.Net application. I have been googling for material and sample on how to do use F5 APM as Identity Provider from Azure ACS but had no luck. Just wondering if someone has done it or know of any resources on how to do it or if it is even possible?
Thanks,
Willson
6 Replies
- Kevin_Stewart
Employee
It should definitely be possible. I'm assuming your ASP.Net application is the relying party (RP) here? In any case, the key requirement is that the RP must be SAML 2.0 compliant. I would review the following three documents:
http://support.f5.com/content/kb/en-us/products/big-ip_apm/manuals/product/apm-saml-configuration-11-4-0/_jcr_content/pdfAttach/download/file.res/BIG-IP_Access_Policy_Manager__SAML_Configuration.pdf
http://msdn.microsoft.com/en-us/library/hh446535.aspx
http://www.windowsazure.com/en-us/develop/net/how-to-guides/access-control/ - wsantoso_131039
Nimbostratus
Thanks Kevin.
In my scenario the relying party for APM will actually be the Windows Azure Access Control Service (ACS) and my asp.net application will be the RP for ACS. My main concern with the scenario is ACS supports SAML tokens over WS-Federation protocol but not SAML-protocol. Can F5 APM be configured as an IdP over WS-Federation protocol?
Regards,
Willson - Kevin_Stewart
Employee
Everything I'm reading suggests that ACS supports ADFSv2, which would be SAML 2.0 compliant. - wsantoso_131039
Nimbostratus
Thanks again Kevin. Unfortunately ACS only supports ADFSv2 using WS-Federation protocol, not SAML protocol.
Not sure if I am allowed to link to another forum, but here is one of the recent discussion on that topic which was answered by an Azure MVP with relevant links to MS resources to back his answers.
http://social.msdn.microsoft.com/Forums/windowsazure/en-US/687be21f-c14f-407f-903a-31f98e0985e3/acsv2-federation-with-adfs-20-using-saml20-protocol - Kevin_Stewart
Employee
Going off the deep end a little, but have you looked at the "developer preview" per Edit 2 in the above reference? - wsantoso_131039
Nimbostratus
Unfortunately, the SAML protocol support in preview is only for using ACS as SAML provider to provide SSO to SAML compliant applications. It's not for ACS to connect to SAML-P identity providers.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com