Security

SAML SSO on Splunkv8.2.4

shangshin
Builder

Hello,

Any changes happened on SAML SSO configuration in the new Splunk v8.2.4 ?

We have an IdP configured to use SSO and it is working in the Splunk v8.1.1. We recently upgraded to v8.2.4 we copied the same authentication.conf from v8.1.1.  Seeing the below error in the Splunkd.log

 

relaystate is empty

RelayState may be missing due to IDP-intiated SAML workflow.

User=<user>@<DOMAIN1.DOMAIN.COM> domain= does not match default domain. Contact your syste administrator for more information about the default domain=saml for this system

 

Any idea how to fix this error?

 

 

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Have you upgraded or copied the authentication.conf to a new instance?

If you copied to a new instance you have to make sure you write all passwords in clear text and restart Splunk.

Also, if this is a new system check from the SAML side that nothing is blocking due to filters.

0 Karma

shangshin
Builder

We got the saml sso working on v8.1.1 and when we migrated to v8.2.4 it works fine.

However,  on the fresh install of v8.2.4 we are getting the same error. I tried rrestarting by eplacing the sslpassword with cleartext, It is not fixing the issue. Still the same errot

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Please check with Splunk support once.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...