Dear sirs (or anybody reading),
we are using the F5 APM as a SP with an external IdP (actually - we do authentication briding - APP → F5 IdP → external IdP) . As a service provider, the exported metadata stated the nameid format is “urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified” and the SAML Auth request doesn’t contain any nameid format statement (what is correct and valid).
The problem stays that the external IdP claims that they support only ‘urn:oasis:names:tc:SAML:2.0:nameid-format:transient’ nameId policy.
Is there a way to configure the nameId policy as a SP? (I don’t think, but I’ll ask, as they’re plenty of features not available via web GUI). Still - I believe the F5 will consume any returned SAML identity assertion (e.g. transient or others).
Best regards Gabriel