Troubleshooting: SP Start URL Does Not Trigger on a Customized SAML Realm

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    SecureAuth IdP uses an SP Start URL to redirect a user to the Service Provider (SP) so it can generate an AuthN request — this covers cases where a user bookmarks the Identity Provider (IdP) realm's page directly instead of navigating there from the SP. On a SAML realm whose post-authentication page has been customized, this SP Start URL redirect does not trigger.

     

    Cause

    The realm's post-authentication page has been customized, and the custom version does not include the code that triggers the SP Start URL redirect.

     

    Resolution:

    1. Back up /Authorized/Saml20SPinitPost.aspx.
    2. Copy /Customized/Saml20SPinitPost.aspx and Saml20SPinitPost.aspx.vb to the /Authorized folder.
    3. On the realm's Post Authentication tab, change the setting to use the standard SAML SP Init by Post option instead of Custom Redirect.

    This example uses SAML SP Init by Post, but the same fix applies to SAML SP Init by redirect as well.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.