Security

SSO on SiteMinder using SAML error message: "**Saml response does not contain group information**"

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I have the following problem:
We configured SSO with Siteminder using SAML.
The problem is that this Siteminder is used only for authentication and not also for profiling so we're not able to configure Splunk roles and when authenticating we receive from Splunk the following error message "Saml response does not contain group information".
Watching Siteminder's logs we can see that arriving on Splunk the following parameters (after authentication on Siteminder's Authentication Schema):

<ns2:Attribute Name="SMUSERNAME" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
    <ns2:AttributeValue>UIDxxxxxx</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name="SMMAIL" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
    <ns2:AttributeValue>xxxx.xxxxx@xxxx.xxxxxx.com</ns2:AttributeValue>
</ns2:Attribute>

Anyone encountered this problem?

Thank you in advance.

Bye.
Giuseppe

0 Karma
1 Solution

suarezry
Builder

Siteminder is releasing the name and email attribute, but no role attribute. You need to configure Siteminder to release this information.

View solution in original post

0 Karma

suarezry
Builder

Siteminder is releasing the name and email attribute, but no role attribute. You need to configure Siteminder to release this information.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...