Forum Discussion
F5 SAML Authentication
I had a battle with F5 support team. If you are interested in it, you can read my blog
http://nano-art.blogspot.co.uk/2013/05/saml-authentication-on-f5-big-ip-part-1.html
(1-4)
After a deep digging, I myself finally figured out the root cause, IDP returned a SAML response which the signature was on response part, but F5 expected a response which signature is on assertion part (WantAssertionsSigned="true").
F5 error message "Digest of SignedInfo mismatch" was not very helpful in my case. Once I had a insight on SAML (actually the hardest part is XML signature), I told myself what joke it was, as we can easily tell the signature is on response part or assertion part from Reference URI in SAML response content.
- Filip_VerlaecktJul 25, 2014Historic F5 AccountSo what exactly did you change to the configuration to make this work then?
- Julio_NavarroMar 23, 2015
Cirrostratus
Hello Mike! How you were able to fix this? Thank you J - boneyardApr 05, 2015
MVP
from what I read from the blog the issue is with what part of the SAML response is signed. the full response or just the assertion. what is signed in your case Navarro?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
