Learn F5 Technologies, Get Answers & Share Community Solutions Join DevCentral

Filter by:
  • Solution
  • Technology
Answers

APM/LTM 12.1: SAML IdP and SP possible in one VE?

Hi, Is it possible to run an SAML IdP and one (or better: more) SPs on one VE? I found a sentence in the doc: In a federation of BIG-IP-Systems, one BIG-IP System acts as a SAML Identity Provider and other BIG-IP systems act as SAML service providers.

Our environment isn't that demanding, so one VE-cluster could take the load easily.

The use case is as follows:

  • APM 12.1.3 for SSO for resources, some of them (still) form-based, one external as SAML-SP up and running.
  • On premises, we have a cluster of 3 servers running OpenExchange, offering HTTP, HTTPS, IMAP and other up and running.
  • An LTM load balancer is set up for that cluster, running for the cluster above, up and running.

Now, I want to have a SAML resource on the SSO-portal for that load balancer for HTTPS. Unsuccessful so far to get that one. AND not sure if that even can be done. ;)

Any clues? Thanks in advance, HP.

0
Rate this Question

Answers to this Question

placeholder+image
USER ACCEPTED ANSWER & F5 ACCEPTED ANSWER

It is possible, I have done that many times in my lab. You need to be careful and configure you vs with different dns names to avoid get the browser to send the apm cookie it has for the Idp session when it access the Sp (the sp will be confused to see apm cookies for a session that is not started)

Keep in mind that you are doubling up the number of sessions in this deployment, one for the Idp and one for the Sp.

0
Comments on this Answer
Comment made 14-Feb-2018 by hpr 66

Thanks Daniel :)

If I'm getting this right, I'd need 3 VSs in this scenario: idp.lab (fed by the AD), portal.lab (the SSO APM), and ox-lb.lab (the load balancer)

The number of sessions you are mentioning are probably a licensing and maybe a performance issue, right?

0
Comment made 14-Feb-2018 by Daniel Varela 701

If I have understood you well, you should be able to apply the SP access profile to ox-lb.lab virtual server.

0
Comment made 15-Feb-2018 by hpr 66

Agreed. :)

Thanks again!

0
placeholder+image
USER ACCEPTED ANSWER & F5 ACCEPTED ANSWER
placeholder+image
USER ACCEPTED ANSWER & F5 ACCEPTED ANSWER

BTW this will only work if you're not using HTTP artifact binding with SAML2.0.

Having said that you can still configure artifact resolution service if you use HTTP for your VSs. That will come in handy if you just want to lab test, but not for production use for obvious reasons.

[Artifact resolution service] https://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-authentication-single-sign-on-11-6-0/27.html

0