F5 is upgrading its customer support chat feature on My.F5.com. Chat support will be unavailable from 6am-10am PST on 1/20/26. Refer to K000159584 for details.

Forum Discussion

Paul_Brown_1284's avatar
Paul_Brown_1284
Icon for Nimbostratus rankNimbostratus
Jun 06, 2013

SAML BIG-IP as SP SHA256 Cipher not accepted

This is the log when we try to hit the SP with sha256:

 

SAML Agent: /Common/TXMAPSAML_act_saml_auth_ag SAML assertion is invalid, error: Unsupported signature alogorithm. rsa-sha1 supported

 

I thought sha256 was supported. I cannot find any way to enable it in the SAML section on the F5. Is anyone else using sha256 from their IdP or is everyone using sha1? sha1 works fine.

 

1 Reply

  • I could do with some guidance on this too! Trying to authenticate against an SP with SAML, and they want SHA-256 signed tokens. I'm sending SHA-1. Apparently 256 became possible in 11.4, and I'm using 11.4.1. Anyone got any clues? Do I need to change the certificate I'm using? Or is this configured somewhere in the APM SAML objects?

     

    Thanks,

     

    Gavin