Bug ID 1396369: APM[Saml IdP] - Support for metadata containing multiple entities

Last Modified: Oct 04, 2024

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
16.1.2, 16.1.2.1, 16.1.2.2, 16.1.3, 16.1.3.1, 16.1.3.2, 16.1.3.3, 16.1.3.4, 16.1.3.5, 16.1.4, 16.1.4.1, 16.1.4.2, 16.1.4.3, 16.1.5, 16.1.5.1

Opened: Nov 10, 2023

Severity: 3-Major

Symptoms

Importing a metadata file containing an <md:EntitiesDescriptor> element which in turn can contain multiple <EntityDescriptor> elements fail to import with: Configuration error: Metadata contains duplicate 'index' (0) in AssertionConsumerService elements. Service Providers must be reconfigured to provide correct metadata. Alternatively, metadata can be manually edited to have a unique 'index' in the range from 0 to 65535 for each AssertionConsumerService element.

Impact

Saml metadata fails to import, and fails to configure.

Conditions

APM acting as the SAML IDP tries to automate the metadata file controlled by a 3rd party vendor and fails to install even when trying to import manually. Because this is a multiple entities metadata file there will be multiple index values for each EntityDescriptor and they may have the same index number.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips