Forum Discussion
SAML: F5 as SP, Azure as IdP Problems with SLO
- Aug 29, 2022
Have you seen the guide below as it is saying the SLO url
/saml/sp/profile/redirect/slo ?
------
From TMOS v16 the SAML SLO endpoint has changed to
./saml/sp/profile/redirect/slo
----------
https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/f5-big-ip-header-advanced
the necessary error messages are already visible in the log and we have already successful decoded the assertion.
The problem is that Azure does not have a SLO url for request and one for response.
an attempt to correct the request url also fails because F5 additionally looks at the url in the assertion and to correct that we only found the way to use iRuleLX but there we have no experience also in terms of performance and interaction. (SLO at Azure only works with the Assertion in the url as parameter and there compress is used)
Have you seen the guide below as it is saying the SLO url
/saml/sp/profile/redirect/slo ?
------
From TMOS v16 the SAML SLO endpoint has changed to
/saml/sp/profile/redirect/slo
.
----------
https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/f5-big-ip-header-advanced
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com