Forum Discussion
Rabbit23_116296
Nimbostratus
Jan 23, 2014SSO options - NTLM integrated SAML assertions
I am trying to use NTLM pre-authentication for SAML assertions.
To conceptualize:
use external logon page in F5 that points to a web service instead of a form the web service authenticates pa...
Kevin_Stewart
Employee
Jan 23, 2014That should in fact work. Assuming you can get the external logon page stuff to work (rarely an easy thing), the only thing the APM IdP needs to send a valid assertion is the session variable that you've specified as the "Assertion Subject Value". So you could technically take the returned username and assign that to the required session variable, and assuming the SP accepts both the assertion and the ID value, you should be good to go. It'd then go something like this (IdP-initiated approach):
- User goes to APM IdP which then redirects to the external logon page
- User authenticates to external logon page via NTLM and is redirected back to APM IdP /my.policy URI with the username and (dummy) POST values
- APM IdP assigns the returned username to the assertion subject value session variable
- APM IdP access policy falls into the resource assignment agent, which specifies an external SP connector, and then redirects the user to the SP with a SAML assertion.
- Bam, you're in.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects