Bug ID 1091509: SAML Artifact resolution service fails to resolve artifacts on same IP after reboot

Last Modified: Mar 30, 2024

Affected Product(s):
BIG-IP APM(all modules)

Opened: Mar 30, 2022

Severity: 3-Major

Symptoms

Unable to authenticate, following error message in the APM log will occur: <DATE> <HOSTNAME> err apmd[13026]: 0149021a:3: /Common/SPTesting_ap:Common:524ba34e: SAML Agent: /Common/SPTesting_ap_act_saml_auth_ag failed to process SAML artifact, error: Failed to resolve Artifact <DATE> <HOSTNAME> err apmd[13026]: 01490000:3: modules/Authentication/Saml/SamlSPAgent.cpp func: "sendSAMLArtifactResolveRq()" line: 6328 Msg: Failed to connect to artifact resolution service. Error (56): Failure when receiving data from the peer <DATE> <HOSTNAME> err apmd[13026]: 01490000:3: modules/Authentication/Saml/SamlSPAgent.cpp func: "resolveSAMLArtifact()" line: 6380 Msg: Error resolving artifact

Impact

ARS will fail to resolve and users will not be able to authenticate.

Conditions

- APM as SP with Artifact Resolution - ARS service uses internal IP - Configured serverssl profile for Artifact Resolution Service in IDP connector

Workaround

Disable the 'serverssl-profile-name' in the IDP connector configuration.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips