Bug ID 668129: BIG-IP as SAML SP support for multiple signing certificates in SAML metadata from external identity providers.

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
12.1.3, 12.1.3.1, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1

Fixed In:
13.1.0, 12.1.3.2

Opened: Jun 06, 2017

Severity: 3-Major

Symptoms

Certain SAML implementations support configuration of multiple signing certificates to be used for signing SAML messages. In these deployments different signing certificates could be used when certificate rotation takes place. Until now BIG-IP as SP only supported single signing certificate from external IdPs. When certificate rotation happens on external IdP, BIG-IP signing verification certificates have to be updated.

Impact

When external IdP starts using new signing certificate previously advertised in metadata, authentication on BIG-IP as SAML SP will fail until administrator adjusts configuration to specify new signature validation certificate on appropriate SAML IdP connector object.

Conditions

External IdP advertises multiple signing certificates in SAML metadata.

Workaround

Signing certificates on BIG-IP as SAML SP can be reconfigured manually.

Fix Information

BIG-IP as SP now supports multiple signing certificates advertised by external identity providers.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips