Bug ID 1582765: SAML Single Logout should use 'SessionIndex' to disconnect SAML sessios

Last Modified: Jul 11, 2024

Affected Product(s):
BIG-IP APM(all modules)

Opened: Apr 29, 2024

Severity: 3-Major

Symptoms

APM SAML IdP locates the external SAML SP connector matching 'EntityID' from configuration and 'Issuer' from SAML SLO request. This implementation may fail if an external SAML SP configures all its SAML SP objects with the same 'EntityID' and some of them initiates the SAML SLO.

Impact

SAML SLO fails

Conditions

-- APM deployed as SAML IdP -- Several external SAML SPs federated with APM SAML IdP -- SAML SP initiates SAML SLO

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips