Forum Discussion
SAML SP post binding to IdP
Generally speaking, it is the IdP that challenges the user for credentials and the SP consumes a trusted assertion from that IdP. The SP wouldn't challenge the user for credentials. So in the barest form, your APM SP would be in front of the app, and the Shibboleth IdP would be a physically separate entity that the client contacts. Now, technically speaking, if the Shibboleth service was also behind an APM VIP, that would more likely just be an SSO configuration where a logon page collects credentials, maybe does some pre-validation, POSTs those credentials to the Shibboleth logon page, and lets the SAML from Shibbloeth pass through. But arguably, if you're putting the IdP behind an APM VIP, why not just let APM be the IdP and save yourself the trouble of maintaining another app service.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
