Forum Discussion
IDP initiated binding with APM as SP
Configuring External IDP connector should be fairly simple. Every SAML provider should be able to export its config via metadata. You should export your IDP config via Metadata and then choose Import as the method for creating an IDP connector.
There is one key difference in enabling IDP-initiated assertions work, you need to specify a RelayState value in the SP SAML configuration field. Check out this page:
https://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-saml-config-guide-11-3-0/4.html
Specifically, on the Relay State:
Optional: In the Relay State field, type a value. The value can be an absolute path, such as hr/index.html or a URI, such as https://www.abc.com/index.html. It is where the service provider redirects users after they are successfully authenticated and have been allowed by the access policy. When APM receives the relay state from the Identity Provider in addition to assertion, then it uses the value received from the IdP to redirect the user. Otherwise, APM uses the value from this configuration.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
