Forum Discussion
SP-initiated SAML SSO doesn't remember landing URL in v 12.0.0
- May 18, 2016
Yes, unfortunately v12.0 introduced a bug on this - BZ 590601 - and it going to be fixed in the later maintenance release of 12.x.x. You can either open a case with support and request it to be linked to that bug and potentially ask about engineering hotfix. However, there is also a workaround that you can attempt to configure to rectify the behavior.
Workaround provided below works when first client request to BIG-IP as SP is 'GET'. This workaround is not applicable when first client request is 'POST'.
SP object can be configured with relay state pointing to the landing URI: %{session.server.landinguri}
After successful authentication, end-user will be redirected to the landing URI (reflected back by IdP in the relay-state).
Please try to implement the workaround and share whether it works for you to address your needs.
Yes, unfortunately v12.0 introduced a bug on this - BZ 590601 - and it going to be fixed in the later maintenance release of 12.x.x. You can either open a case with support and request it to be linked to that bug and potentially ask about engineering hotfix. However, there is also a workaround that you can attempt to configure to rectify the behavior.
Workaround provided below works when first client request to BIG-IP as SP is 'GET'. This workaround is not applicable when first client request is 'POST'.
SP object can be configured with relay state pointing to the landing URI: %{session.server.landinguri}
After successful authentication, end-user will be redirected to the landing URI (reflected back by IdP in the relay-state).
Please try to implement the workaround and share whether it works for you to address your needs.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
