Forum Discussion
SAML BIG-IP as SP SHA256 Cipher not accepted
This is the log when we try to hit the SP with sha256:
SAML Agent: /Common/TXMAPSAML_act_saml_auth_ag SAML assertion is invalid, error: Unsupported signature alogorithm. rsa-sha1 supported
I thought sha256 was supported. I cannot find any way to enable it in the SAML section on the F5. Is anyone else using sha256 from their IdP or is everyone using sha1? sha1 works fine.
1 Reply
- Gavin_Connell-O
Nimbostratus
I could do with some guidance on this too! Trying to authenticate against an SP with SAML, and they want SHA-256 signed tokens. I'm sending SHA-1. Apparently 256 became possible in 11.4, and I'm using 11.4.1. Anyone got any clues? Do I need to change the certificate I'm using? Or is this configured somewhere in the APM SAML objects?
Thanks,
Gavin
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com