Security

SSO on SiteMinder using SAML error message: "**Saml response does not contain group information**"

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I have the following problem:
We configured SSO with Siteminder using SAML.
The problem is that this Siteminder is used only for authentication and not also for profiling so we're not able to configure Splunk roles and when authenticating we receive from Splunk the following error message "Saml response does not contain group information".
Watching Siteminder's logs we can see that arriving on Splunk the following parameters (after authentication on Siteminder's Authentication Schema):

<ns2:Attribute Name="SMUSERNAME" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
    <ns2:AttributeValue>UIDxxxxxx</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name="SMMAIL" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
    <ns2:AttributeValue>xxxx.xxxxx@xxxx.xxxxxx.com</ns2:AttributeValue>
</ns2:Attribute>

Anyone encountered this problem?

Thank you in advance.

Bye.
Giuseppe

0 Karma
1 Solution

suarezry
Builder

Siteminder is releasing the name and email attribute, but no role attribute. You need to configure Siteminder to release this information.

View solution in original post

0 Karma

suarezry
Builder

Siteminder is releasing the name and email attribute, but no role attribute. You need to configure Siteminder to release this information.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...