Loading...
Loading...
When the BIG-IP as SAML IdP is configured to generate assertions larger than 32 KB, occasionally the BIG-IP system might not send the entire assertion as part of the HTTP response to the client, leaving the browser in a waiting state for the rest of the assertion to arrive.
Occasionally, APM end users will not be able to receive full SAML assertion, and therefore, authentication with SAML SP will fail.
-- The BIG-IP system is configured as SAML IdP. -- IdP is configured to include either list of (large) attributes, with assertion size exceeding 32 KB.
When applicable, reconfigure SAML attributes to reduce the size of the generated assertion, i.e., remove unnecessary attributes from the SAML configuration.
The BIG-IP system now supports generating assertions larger than 32 KB.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.