Forum Discussion
David_123856
Nimbostratus
Jul 21, 2014Is there a way to manipulate SAMLRequest in an iRule
I have an issue with an SP initiated SAML service where they have multiple Instances, but only provide one Issuer from all of them.
In the Redirect request I can determine which instance from the Re...
Michael_Koyfman
Cirrocumulus
Jul 21, 2014What exactly is your situation? Your SP has different instances and you need to service them by different IDP configs on your APM?
David_123856
Nimbostratus
Jul 21, 2014In point form caus its easier to type :):
* The SP provides multiple instances - eg Test, Dev, QA, etc,
* Each Instance at the SP has its own AssertionConsumerURL (eg. https://ACU/saml?Instance=QA
* SP initiated SAML requests has the same SP Issuer inside the encoded token, but a different relaystate so I can tell from that url param which instance its for
So I had set up 1 External SP config for each instance, and 1 idp Config for each instance, but as all the requests have the same SP Issuer the F5 matches the first idp service and then returns to that ones bound SP config.
Have to use SO initiated due t links sent by the Service with no capacity to change the urls
Unless I can bind multiple SPs to one idp and it can work out via the relay state which SP to use?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects