Forum Discussion
SAML IdP fails to validate the redirect signature
I'd like to address some of these concerns.
-
I didn't believe until I saw it for myself, but you appear to be correct concerning the SigAlg and Signature parameters in the SAMLRequest HTTP-Request binding. An APM SP (perhaps incorrectly), when configured to sign authentication requests will embed the signature and signature algorithm in the encoded SAMLRequest. I would recommend opening a case to address this.
-
A multi-domain access policy is not in any way related to SAML, though they have similar characteristics. As to your findings you are again correct. The redirect from the logon URI produces a GET request, and would lose any initial POST to the application URI. There are conceivably ways around this though.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com