For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

CDG's avatar
CDG
Icon for Nimbostratus rankNimbostratus
Apr 20, 2016

SAML SP-initiated no redirection

I have setup a BigIP as IdP (SSO Portal) when we do a SP-initiated connection the redirection to the SP after AD auth is not happening. IDP-Initiated works properly from a Webtop/SAML Resource

 

The browser get stuck at https://login.domain.com/saml/idp/profile/redirectorpost/sso?SAMLRequest=nVNdT9swFP0rkd8dJ2kDw2oqdRS0......

 

Is there any explanation that would explain why?

 

In the setup of the IdP service

 

Is there any problem if the URL of the IdP Entity ID is setup like this? https://login.domain.com/id1

 

VPE:

 

2 Replies

  • CDG's avatar
    CDG
    Icon for Nimbostratus rankNimbostratus

    SP-initiated was not working because there was an error in the configuration of the SP Connector.

     

    From the SP metadata...the service provider configured the use=signing and use=encryption with a certificate.

     

    The APM was expecting the SP to include a signature in their AuthN Request for SP-Initiated connections but that was not the case. Modifying the SAML SP Connector/Security Settings/ "Will be signed" from yes to no fixed the problem.

     

    • f5learn_164388's avatar
      f5learn_164388
      Icon for Nimbostratus rankNimbostratus
      Thank you so much for posting this. We were able to fix similar issue we ran into.