- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi all,
we are trying to configure Splunk on premise (7.3.6) to work with SAML and ADFS but we are stuck with some errors:
with signedAssertion = false we see in internal logs:
ERROR Saml - Failed to parse issuer. Could not evaluate xpath expression //saml:Assertion/saml:Issuer or no matching nodes found. No value found in SamlResponse for key=//saml:Assertion/saml:Issuer
with signedAssertion = true
ERROR UiSAML - Verification of SAML assertion using the IDP's certificate provided failed. Error: start node xmlSecNodeSignature not found in document
Any suggestions?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We solved our problem by following Splunk support suggestion to remove encryption from ADFS as specified in chapter 13 of this guide:
https://www.splunk.com/en_us/blog/tips-and-tricks/configuring-microsofts-adfs-splunk-cloud.html
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Had the same error message to an adfs server with encryption and in my case this worked, dont know if it is correct.
I added the encrypted private key to signAuthnRequest certificate, which is this authentication.conf parameter:
[saml]
clientCert = cert_and_encrypted_private_key.pem
The password of the encypted private key was configured to the parameter sslPassword of the same stanza
sslPasswort =
No this parameter could be set to true:
signAuthnRequest = true
and reloaded authentication to let the sslPasswort be hashed.
Worked for me.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We solved our problem by following Splunk support suggestion to remove encryption from ADFS as specified in chapter 13 of this guide:
https://www.splunk.com/en_us/blog/tips-and-tricks/configuring-microsofts-adfs-splunk-cloud.html
