Forum Discussion

CDG's avatar
CDG
Icon for Nimbostratus rankNimbostratus
May 03, 2016

SAML IdP Signing Encryption

BIG-IP 11.5.1 Build 4.0.128 Hotfix HF4

 

I have setup the BIG-IP as IdP.

 

A Service Provider (External SP Connectors) required two different certificates one for Auth request signing and one for assertion encryption. In the SAML SP connector we only have the option to select one certificate for both.

 

Is it possible from tmsh to set this particular requirement?

 

Thanks,

 

Now if I set the Auth Request sent to this device by SP ... Will be signed --> Yes.

 

I get from APM log:

 

SSOv2 Digest from SAML message is invalid SSOv2 Error(12) Signature verification failed for SAML Authentication Request