<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAML response from ADFS in Security</title>
    <link>https://community.splunk.com/t5/Security/SAML-response-from-ADFS/m-p/544894#M12161</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;we are trying to configure Splunk on premise (7.3.6) to work with SAML and ADFS but we are stuck with some errors:&lt;/P&gt;&lt;P&gt;with&amp;nbsp;signedAssertion = false we see in internal logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ERROR Saml - Failed to parse issuer. Could not evaluate xpath expression //saml:Assertion/saml:Issuer or no matching nodes found. No value found in SamlResponse for key=//saml:Assertion/saml:Issuer&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with&amp;nbsp;signedAssertion = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ERROR UiSAML - Verification of SAML assertion using the IDP's certificate provided failed. Error: start node xmlSecNodeSignature not found in document&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
    <pubDate>Tue, 23 Mar 2021 09:23:43 GMT</pubDate>
    <dc:creator>llopreiato</dc:creator>
    <dc:date>2021-03-23T09:23:43Z</dc:date>
    <item>
      <title>SAML response from ADFS</title>
      <link>https://community.splunk.com/t5/Security/SAML-response-from-ADFS/m-p/544894#M12161</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;we are trying to configure Splunk on premise (7.3.6) to work with SAML and ADFS but we are stuck with some errors:&lt;/P&gt;&lt;P&gt;with&amp;nbsp;signedAssertion = false we see in internal logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ERROR Saml - Failed to parse issuer. Could not evaluate xpath expression //saml:Assertion/saml:Issuer or no matching nodes found. No value found in SamlResponse for key=//saml:Assertion/saml:Issuer&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with&amp;nbsp;signedAssertion = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ERROR UiSAML - Verification of SAML assertion using the IDP's certificate provided failed. Error: start node xmlSecNodeSignature not found in document&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 09:23:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/SAML-response-from-ADFS/m-p/544894#M12161</guid>
      <dc:creator>llopreiato</dc:creator>
      <dc:date>2021-03-23T09:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: SAML response from ADFS</title>
      <link>https://community.splunk.com/t5/Security/SAML-response-from-ADFS/m-p/546332#M12178</link>
      <description>&lt;P&gt;We solved our problem by following Splunk support suggestion to remove encryption from ADFS as specified in chapter 13 of this guide:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/configuring-microsofts-adfs-splunk-cloud.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/tips-and-tricks/configuring-microsofts-adfs-splunk-cloud.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 06:57:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/SAML-response-from-ADFS/m-p/546332#M12178</guid>
      <dc:creator>llopreiato</dc:creator>
      <dc:date>2021-04-01T06:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: SAML response from ADFS</title>
      <link>https://community.splunk.com/t5/Security/SAML-response-from-ADFS/m-p/673936#M17544</link>
      <description>&lt;P&gt;Had the same error message to an adfs server with encryption and in my case this worked, dont know if it is correct.&lt;BR /&gt;&lt;BR /&gt;I added the encrypted private key to signAuthnRequest certificate, which&amp;nbsp; is this authentication.conf parameter:&lt;BR /&gt;&lt;BR /&gt;[saml]&lt;BR /&gt;clientCert = cert_and_encrypted_private_key.pem&lt;BR /&gt;&lt;BR /&gt;The password of the encypted private key was configured to the parameter sslPassword of the same stanza&amp;nbsp;&lt;BR /&gt;sslPasswort =&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;No this parameter could be set to true:&lt;BR /&gt;&lt;BR /&gt;signAuthnRequest = true&lt;BR /&gt;&lt;BR /&gt;and reloaded authentication to let the sslPasswort be hashed.&lt;BR /&gt;&lt;BR /&gt;Worked for me.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 13:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/SAML-response-from-ADFS/m-p/673936#M17544</guid>
      <dc:creator>hschuhkn</dc:creator>
      <dc:date>2024-01-11T13:16:19Z</dc:date>
    </item>
  </channel>
</rss>

