Bug ID 1354345: Including RelayState while validating SLO Response Signature

Last Modified: Sep 24, 2024

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
15.1.8, 15.1.8.1, 15.1.8.2, 15.1.9, 15.1.9.1, 15.1.10, 15.1.10.2, 15.1.10.3, 15.1.10.4, 15.1.10.5

Opened: Sep 21, 2023

Severity: 2-Critical

Symptoms

The parameter 'RelayState' parameter received in SLO Response from IDP is not included in the signature validation when BIG-IP is used as SP.

Impact

BIG-IP fails in validating the Signature of SLO Response.

Conditions

BIG-IP as SP does not include 'RelayState' while validating the signature of SLO Response.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips