Forum Discussion
Is there an APM SAML error legend or documentation?
The log message is not documented in
https://techdocs.f5.com/kb/en-us/products/big-ip_ltm/releasenotes/related/log-messages.html!
I've ran into this issue today and came across this article. I found the message
SAML assertion is invalid, error: Invalid Session, possible use of different host names to access SAML SPas reason for my issue. The reason for this issue is very simple: SameSite settings in APM access profile.
In my case, SameSite was enabled and set to strict in my access profile (default in APM 17.1+). This caused the browser to stop sending the MRHSession cookie to the APM when I were redirected back from the IDP to the APM (with the assertion). A new session was created, indicated by
New session from client IP x.x.x.xmessages in the log. Once again the behavior of the BIG-IP/APM is not very helpful to discover the real issue. On the other hand, the APM is not able to discover, that this is a recurring client, if the session cookie is not sent...at the end it's SameSite and the browser. 😒
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
