Bug ID 440468: SAML: APD crashes on Assertion without SessionIndex in AuthnStatement when SLO is configured

Last Modified: Apr 11, 2024

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
11.6.2 HF1, 11.4.0, 11.4.1

Fixed In:
11.5.1 HF5, 11.4.1 HF6, 11.4.0 HF8

Opened: Dec 11, 2013

Severity: 3-Major

Related Article: K14928

Symptoms

When the BIG-IP system is configured as a SAML Service Provider (SP), APD can crash if the IdP connector object that is used specifies a single logout URL. A crash occurs only when the SP receives a SAML assertion that does not include a SessionIndex attribute in the AuthnStatement element.

Impact

APD crashes, SAML authentication fails.

Conditions

1. IdP sends Assertion without SessionIndex element in AuthnStatement. 2. IdP connector on BIG-IP has single-logout-url specified (not empty).

Workaround

To work around the problem: 1. Reconfigure IdP to send Assertion with SessionIndex attribute in AuthnStatement element, or 2. Clear single-logout-url in IdP connector object on the BIG-IP system.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips