Dashboards & Visualizations

Why are we getting SAML authentication error "Unable to parse the payload received as a part if idp metadata file or xml." on our Splunk 6.3.1 search head?

metadata
Engager

We tried to enable SAML authentication for our Splunk 6.3.1 Search Head. For this, we tried to import the IdP metadata XML file, but this fails with the following message:

"Unable to parse the payload received as a part if idp metadata file or xml."

We tried to import the IdP xml file provided at Step 3 "Obtain the IdP meta data" of this blog: http://blogs.splunk.com/2013/03/28/splunkweb-sso-samlv2/ but we do obtain the exact same message:

"Unable to parse the payload received as a part if idp metadata file or xml."

Is there a specific format we need to comply to ?

Any help would be very much appreciated.

Thanks

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

I have a hunch that you're character encoding is bad. Such as you're copying the IDP metadata file/xml to notepad in windows, and then saving and/or copy and pasting to linux search head. Or visa versa you're copying from linux to windows.

You should try using dosutils if in linux. apt-get dosutils, etc... it gives you commands called dos2unix and unix2dos. SO if you're uploading to linux, try running dos2unix on the IDP xml file first, and then maybe use cat to write the file to your console, then copy and paste into the search head on step 3.

View solution in original post

jkat54
SplunkTrust
SplunkTrust

I have a hunch that you're character encoding is bad. Such as you're copying the IDP metadata file/xml to notepad in windows, and then saving and/or copy and pasting to linux search head. Or visa versa you're copying from linux to windows.

You should try using dosutils if in linux. apt-get dosutils, etc... it gives you commands called dos2unix and unix2dos. SO if you're uploading to linux, try running dos2unix on the IDP xml file first, and then maybe use cat to write the file to your console, then copy and paste into the search head on step 3.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...