Forum Discussion
jamed_40076
Jun 08, 2016Nimbostratus
SP SAML authentication fails after token signing cert update
We're using ADFS 3.0 as our IDP, and a virtual F5 (BIG-IP 11.6.0 Build 0.0.401 Final) as the SP. Our config worked for the past year, but we needed to renew our token signing certificate. We generate...
- Jun 08, 2016
Not sure what exactly is happening, but you are running a pretty old version of the BIG-IP. I would recommend two things:
- Export metadata from ADFS and import them to BIg-IP anew, and essentially create new IDP connector and bind it to SP config.
- Upgrade to 11.6.1 if 1 does not succeed in moving you forward past this.
- If both 1 and 2 fail to solve it, open a ticket with support to investigate further.
Mike_99062
Mar 02, 2017Nimbostratus
FYI, We ran into the same issue, with a similar setup running on 11.6.1 base. The IdP XML file we received didn't assign the IdP's Assertion Verification Certificate in Security Settings/Certificate Settings to the provided Certificate from the XML file. Once the External IdP Connector configuration was updated, SAML SP Auth was successful. Hope this helps someone.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects