Forum Discussion

ChrisTheMonkey's avatar
ChrisTheMonkey
Icon for Nimbostratus rankNimbostratus
Nov 04, 2019

SAML Redirection Not Working

Hello,

 

   I'm attempting to setup a SAML configuration where KnowBe4 is the SP and our APM's are the IDP. I have read:

 

https://clouddocs.f5.com/products/agc/5.0/saml-saas-applications/knowbe4.html

 

I followed it the best I could (it's pretty generic), but it's not working. Let me explain what I'm seeing…

 

The APM presents the login form fine, and I'm able to properly authenticate against the domain. Where I think the problem is coming in is when the IDP *should* be redirecting the user back to the SP. What I see when I follow the requests is:

 

  1. User submits form, the form is submitted to the page my.policy on the APM
  2. The APM then redirects the browser to /idp?SAMLRequest=<the encoded request packet>
  3. This is where things stop, the redirect from step 2 times out

 

When I watch another, working SAML application I see that after step 2 the browser is redirected to a URL starting with "/saml/idp/profile/redirectorpost/sso?SAMLRequest=". That page redirects the browser back to the SP.

 

Has anybody seen something like this before? Am I right in thinking that the URL that the form submission redirects to is incorrect in the KnowBe4 version of the configuration? If so, what magic incantation do I use to fix it?

 

I used the Guided Configuration to setup to SSO application, and I used the KnowBe4 application option