<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ProxySSO authentication failed to process groups header in Security</title>
    <link>https://community.splunk.com/t5/Security/ProxySSO-authentication-failed-to-process-groups-header/m-p/391971#M9599</link>
    <description>&lt;PRE&gt;&lt;CODE&gt;ERROR UserManagerPro - Error initializing authentication - ProxySSO authType allowed only with SSOMode=strict in web.conf.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Problem solved ...&lt;/P&gt;</description>
    <pubDate>Mon, 15 Apr 2019 09:42:59 GMT</pubDate>
    <dc:creator>chclemence</dc:creator>
    <dc:date>2019-04-15T09:42:59Z</dc:date>
    <item>
      <title>ProxySSO authentication failed to process groups header</title>
      <link>https://community.splunk.com/t5/Security/ProxySSO-authentication-failed-to-process-groups-header/m-p/391969#M9597</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm trying to configure Proxy SSO authentication, with PingAccess, for Splunk Enterprise v7.2.5.1.&lt;BR /&gt;
But whatever I try and configure on Splunk side, I obtain this message in the splunkd logs :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;DEBUG UiAuth - Value of header returned=&amp;lt;user id&amp;gt;
INFO UiAuth - ProxySSO authType not configured, no groups header processing
ERROR UiAuth - user=&amp;lt;user id&amp;gt; action=login status=failure reason=sso-failed useragent="Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.91 Safari/537.36" clientip=&amp;lt;proxy sso ip&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is my authentication.conf file:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[authentication]
authType = ProxySSO

[roleMap_proxySSO]
user_0 = P_SPLUNK_CONSULT-DATA-ALL_PUBLIC
user_1 = P_SPLUNK_CONSULT-DATA-IT_INTERNE
user_2 = P_SPLUNK_CONSULT-DATA-IT_CONFIDENT
admin = pg_splunk
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And my web.conf file:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[settings]
SSOMode = permissive
trustedIP = 127.0.0.1,&amp;lt;proxy sso ip&amp;gt;
remoteUser = REMOTE_USER
remoteGroups = REMOTE_GROUPS
remoteGroupsQuoted = false
allowSsoWithoutChangingServerConf = 1
enableSplunkWebSSL = 0
enableWebDebug = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The SSO debug page looks well, but the line "Value of REMOTE_GROUPS" remains empty (the user is ok).&lt;BR /&gt;
And at the bottom of the page, in the "other http headers", there is the header "REMOTE_GROUPS" which contains the right list of groups, separated by commas, without quotes.&lt;/P&gt;

&lt;P&gt;According to the groups list and the group mapping rules, the user should obtain the first 3 roles (user_0, user_1, user_2).&lt;/P&gt;

&lt;P&gt;What did I miss ??&lt;/P&gt;

&lt;P&gt;Christophe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:58:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/ProxySSO-authentication-failed-to-process-groups-header/m-p/391969#M9597</guid>
      <dc:creator>chclemence</dc:creator>
      <dc:date>2020-09-29T23:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: ProxySSO authentication failed to process groups header</title>
      <link>https://community.splunk.com/t5/Security/ProxySSO-authentication-failed-to-process-groups-header/m-p/391970#M9598</link>
      <description>&lt;P&gt;Small update:&lt;/P&gt;

&lt;P&gt;I added a default role in authentication.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [authentication]
 authSettings = my_proxy
 authType = ProxySSO

 [my_proxy]
 defaultRoleIfMissing = user
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And the behaviour is the same, I receive an "unauthorized" error, even with the "defaultRoleIfMissing" configuration !&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 14:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/ProxySSO-authentication-failed-to-process-groups-header/m-p/391970#M9598</guid>
      <dc:creator>chclemence</dc:creator>
      <dc:date>2019-04-08T14:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: ProxySSO authentication failed to process groups header</title>
      <link>https://community.splunk.com/t5/Security/ProxySSO-authentication-failed-to-process-groups-header/m-p/391971#M9599</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;ERROR UserManagerPro - Error initializing authentication - ProxySSO authType allowed only with SSOMode=strict in web.conf.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Problem solved ...&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2019 09:42:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/ProxySSO-authentication-failed-to-process-groups-header/m-p/391971#M9599</guid>
      <dc:creator>chclemence</dc:creator>
      <dc:date>2019-04-15T09:42:59Z</dc:date>
    </item>
  </channel>
</rss>

