Security

SSO on SiteMinder using SAML error message: "**Saml response does not contain group information**"

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I have the following problem:
We configured SSO with Siteminder using SAML.
The problem is that this Siteminder is used only for authentication and not also for profiling so we're not able to configure Splunk roles and when authenticating we receive from Splunk the following error message "Saml response does not contain group information".
Watching Siteminder's logs we can see that arriving on Splunk the following parameters (after authentication on Siteminder's Authentication Schema):

<ns2:Attribute Name="SMUSERNAME" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
    <ns2:AttributeValue>UIDxxxxxx</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name="SMMAIL" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
    <ns2:AttributeValue>xxxx.xxxxx@xxxx.xxxxxx.com</ns2:AttributeValue>
</ns2:Attribute>

Anyone encountered this problem?

Thank you in advance.

Bye.
Giuseppe

0 Karma
1 Solution

suarezry
Builder

Siteminder is releasing the name and email attribute, but no role attribute. You need to configure Siteminder to release this information.

View solution in original post

0 Karma

suarezry
Builder

Siteminder is releasing the name and email attribute, but no role attribute. You need to configure Siteminder to release this information.

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...