Forum Discussion

hpr_220139's avatar
hpr_220139
Icon for Nimbostratus rankNimbostratus
Feb 14, 2018

APM/LTM 12.1: SAML IdP and SP possible in one VE?

Hi, Is it possible to run an SAML IdP and one (or better: more) SPs on one VE? I found a sentence in the doc: In a federation of BIG-IP-Systems, one BIG-IP System acts as a SAML Identity Provider and other BIG-IP systems act as SAML service providers.

 

Our environment isn't that demanding, so one VE-cluster could take the load easily.

 

The use case is as follows:

 

  • APM 12.1.3 for SSO for resources, some of them (still) form-based, one external as SAML-SP up and running.
  • On premises, we have a cluster of 3 servers running OpenExchange, offering HTTP, HTTPS, IMAP and other up and running.
  • An LTM load balancer is set up for that cluster, running for the cluster above, up and running.

Now, I want to have a SAML resource on the SSO-portal for that load balancer for HTTPS. Unsuccessful so far to get that one. AND not sure if that even can be done. ;)

 

Any clues? Thanks in advance, HP.

 

4 Replies

  • It is possible, I have done that many times in my lab. You need to be careful and configure you vs with different dns names to avoid get the browser to send the apm cookie it has for the Idp session when it access the Sp (the sp will be confused to see apm cookies for a session that is not started)

     

    Keep in mind that you are doubling up the number of sessions in this deployment, one for the Idp and one for the Sp.

     

    • Henrik_S's avatar
      Henrik_S
      Icon for Nimbostratus rankNimbostratus

      Could you please elaborate on why this does not work with HTTPS and artifact binding on the same BIG-IP instance? I see the TCP handshake from the host not beein followed up by a client_hello for TLS but rather sending a straight HTTP-post.

       

      When I read your comment I changed to HTTP and that works, but is really suboptimal..