The IdP returned role Distinguished Name (DN) 'cn=splunk_dns,ou=groups,dc=foo,dc=bar', which matches configured role map Common Name (CN) splunk_dns'. This role DN has now been locked to the role map CN, using the 'dns' role. Future assertions that contain this CN but do not match the locked DN will be rejected. Seeing multiple messages like this, every time we login. Is something wrong with our config? how to stop this notification...
... View more