Forum Discussion

Daniel_W__13795's avatar
Daniel_W__13795
Icon for Nimbostratus rankNimbostratus
Aug 06, 2015

Use Edge Session for authentication on SAML IdP Virtual Server

I'm running APM for different use cases. One use case is connecting mobile devices with Edge Client. They authenticate with user based certificates. On the same box, I have another APM access profile running that does SAML authentication and provides an IDP service. I now want that Edge Client connected users don't need to authenticate a second time, meaning that the SAML IDP access profile leverages the authentication information we already received when authenticating the user with Edge Client.

 

Has anybody implemented a good approach for that?

 

Thanks in advance for your support.

 

2 Replies

  • I just found out that the SSO works, when Edge Client users and SAML IdP VS are in the same route domain. In my setup, the edge client users are directed to a customers route domain, the SAML IdP resides on another route domain for shared services.

     

    Any ideas how to solve that without changing my route domain concept?

     

  • kunjan's avatar
    kunjan
    Icon for Nimbostratus rankNimbostratus

    Might be possible to create a layered VS on customer RD with pool member pointing to SAML IdP on it's RD, with strict isolation disabled.