Splunk SOAR (f.k.a. Phantom)

Splunk Phantom SAML SAML2 authentication error Signature missing for response

eugeneAq
Engager

We were configuring our phantom instance for saml sso login and we are encountering the following error.

SAML2 authentication error

Signature missing for response

We have already configured every field here.
Are we missing anything? Would we need to configure the idp chains or certficates.

0 Karma

ramanpuri2510
Loves-to-Learn Lots

Hi I am doing OKTA SAML integration with Phantom and getting the below error.

SAML2 Authentication Error'NoneType' object has no attribute 'require_signature

Can i know if any option to make the AuthnRequestsSigned="true to false? or any other suggestions.. I have tried disabling the signing on both okta and phantom

0 Karma

sam_splunk
Splunk Employee
Splunk Employee

It sounds like your IdP is not signing the assertion.  You'll want to want to ensure that is occuring. You can install a browser plugin like SAML-TRACER  to view the assertions as they make their way to Phantom to ensure the signature is present. 

While it may not be your IDP - https://github.com/phantomcyber/phantom-community-projects/blob/master/Questions/SSO/SAML/PingFedera... has some details of setting up SSO with SAML (that doc is PingFederate specifically).

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...