Forum Discussion

igorzhuk's avatar
igorzhuk
Icon for Altostratus rankAltostratus
Jun 10, 2018

Saml SSO 4 SP with same IDP

My Big IP As SP 
I have 4 VS configured with APM saml SSO 
Every VS configured with Saml SP Services 
all the SP services bind to same IDP connector
when USER accept in APM they can move to another VIP and when a client in another VS click to start SSO 
they automatically authorized because Because he made an identification with saml 
I can solve this issue with some way
  • Hi Igor.

     

    Can you explain what is your issue. And what's you need exactly?

     

    Regards

     

  • Hi Youssef I have 4 VS on my F5 All VS configured with SSO saml authentication with same IDP when I connect to VS after authentication I permit to MYAPP

     

    after I go to my other VS in the same session I try to Join MYAPP2 I don't need authentication with IDP because I don't do logout from MYAPP

     

  • Hi Igor.

     

    In fact it's a normal behaviour. You have 4 Service provider bind to the same IDP (authentication federation).

     

    According to the timeout that you set on your IDP, all SP don't need authentication while IDP session is still alive.

     

    So the behaviour that you indicate is normal and wanted in this kind of architecture.

     

    But If I understand, you want that user have to re-authenticate for each application? In this case why thou federated authentication?

     

    Regards