Security

Integration with Deepnet Two Factor authtentication using SAML

ramesh_babu71
Path Finder

Hello All,

We are unable to integrate Splunk 6.5.2 with Deepnet 2FA using SAML. When I access the Splunk login page then it is perfectly redirected to IDP login page then after provided the user credentials this error page gets displayed. The error says The saml response does not contain group information.

Authentication.conf

[authentication]
authSettings = saml
authType = SAML

[roleMap_SAML]
admin = deepnetgroup;

[saml]
entityId = splunkEntityId
fqdn = http://rhel7
idpCertPath = /opt/splunk/etc/auth/SSOServer.crt
idpSLOUrl = https://dualshield.wipro.com:8074/appsso/logout?DASApplicationName=Splunk WebSSO
idpSSOUrl = https://dualshield.wipro.com:8074/appsso/login?DASApplicationName=Splunk WebSSO

issuerId = https://dualshield.wipro.com:8074

redirectPort = 8000
signAuthnRequest = true
signatureAlgorithm = RSA-SHA1
signedAssertion = true
sloBinding = HTTPRedirect

sslKeysfile = /opt/splunk/etc/auth/server.pem

clientCert = /opt/splunk/etc/auth/server.pem

sslKeysfilePassword = $1$3umknA8lnEHb

sslPassword = $1$3umknA8lnEHb
ssoBinding = HTTPRedirect

Tags (2)
0 Karma

ramesh_babu71
Path Finder

Hi All,

I contacted Deepnet support (Vendor). They assisted us with this.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share the resolution.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ramesh_babu71
Path Finder

Hi Rich,

Deepnet has published full steps of integration in their wiki page

http://wiki.deepnetsecurity.com/pages/viewpage.action?pageId=2818969

0 Karma

suarezry
Builder

Use this browser tool to trace your SAML response:
https://addons.mozilla.org/en-US/firefox/addon/saml-tracer/

Did your IdP include the role information in the response?

(...and your role name 'deepnetgroup;' includes a semicolon. Is this by design?)

0 Karma
Get Updates on the Splunk Community!

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...