SAML Metadata Import Errors when Federation Metadata XML file is larger than 64KB

SAML Metadata Import Errors when Federation Metadata XML file is larger than 64KB

book

Article ID: CTX428181

calendar_today

Updated On:

Description

The following messages are observed at the logs: 
 

Mar  3 15:55:42 <local0.debug>  GMT LAB01ADC1 0-PPE-0 : default AAATM Message 1903432 0 :  "Parsing sso url"
Mar  3 15:55:42 <local0.debug>  GMT LAB01ADC1 0-PPE-0 : default AAATM Message 1903433 0 :  "Parsing sso url"
Mar  3 15:55:42 <local0.info>  GMT LAB01ADC1 0-PPE-0 : default AAATM Message 1903434 0 :  "Unable to parse metadata imported" <--- This message.

Resolution

2 Possible workarounds:

1.- Manually Configure SAML data (do not use metadata URL)

2.- Reduce the Metadata XML file size to less than 64KB at the IDP so the ADC can process it without errors.

Problem Cause

Federation metadata XML is larger than we can process at the ADC. We have a metadata file size limitation of 64K by design at the ADC to import

This is documented under our internal Bug/Enhancement database, to increase that file limit at the ADC, but It is pending to be implemented with no defined release time yet

Issue/Introduction

SAML Metadata Import Errors when Federation Metadata XML file is larger than 64KB - Known behavior with an enhancement request under-way.