Forum Discussion
SAML as server-side SSO
Hello,
I'm looking to obtain more information about how to configure an app that is behind APM to use SAML. I believe the app behind the APM would be the SP, with the BIG-IP still performing IdP functions, but hiding most of this from the end user.
This is referring to the ability to choose SAML connectors for SSO in an access policy's Authentication Domain list, shown in the screenshot below:
The KB seems to be lacking in documentation specifically for this configuration. Would anyone be able to point me in the right direction?
Thanks. Josh
Hi Josh,
I'm not sure the SAML configuration works the way you want.
When you have a backend application configured as a SAML Service Provider, you have to define your bigip device as an IDP and establish the trust between each peer.
You have to configure the IDP object on the bigip device, import metadata form the SP to build the SP Connector and bind this SP connector to the IDP profile.
Then, you can assign the IDP profile to the SSO options of your Access profile used for F5 as IDP.
Hope it helps
Yann
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com