Technical Forum
Ask questions. Discover Answers.
cancel
Showing results for 
Search instead for 
Did you mean: 

Setting up SAML as F5 IDP to work with Amazon Cognito

jdewing
Cirrus
Cirrus

Has anyone setup F5 SAML to work with Amazon Cognito.  I'm getting error message "Invalid RelayState from Identity Provider".

I tried with different endpoint for Relay State.  No Luck.

 

Local IdP Services
 
Assertion Settions:
  • Assertion Subject Type: Persistent Identifier
  • Assertion Subject Value: %{sessionlogon.last.username)
  • Authentication Context Class Reference: urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
 
SAML attributes:
 
External SP Connectors Configuration:
Service Provider Entity ID: urn:amazon:cognito:sp:us-gov-west-1_PewQe5b4r
Relay State: ????

Metadata XML file has been uploaded to Amazon Cognitio

 

 

3 REPLIES 3

AubreyKingF5
Community Manager
Community Manager

Have you turned logging on and reviewed the auth logs yet?

Hi,

I hope you have insert a dot here: 

  • Assertion Subject Value: %{session.logon.last.username)

For relay state you could add the following variable: %{session.server.landinguri}
Cheers,
Kees

Leslie_Hubertus
Community Manager
Community Manager

Hi @jdewing  - did the answers from Kees or Aubrey help you out? Are you still looking for a solution? Did you solve it another way?