Version Affected: All -- the version range differs by cause, noted individually below.
Overview
Generating or downloading a realm's SAML metadata can fail. There are two independent causes with different symptoms:
- See Cause 1 - Downloading the metadata from the New Experience interface fails with a missing-metadata error response.
- See Cause 2 - Generating the metadata on the Classic interface's SAML properties page shows "Error generating metadata file."
These causes are not related, so a fix for one cause will not resolve the other cause.
In this article
- Cause 1: New Experience Metadata Download Fails (Missing Issuer)
- Cause 2: Classic Interface Metadata Generation Fails (Missing Required Fields)
Cause 1: New Experience Metadata Download Fails (Missing Issuer)
Applies to versions 21.04-24.04, in both Cloud and Hybrid deployments.
Attempting to download SAML metadata for a realm from the New Experience interface can fail, with the browser showing an error response instead of the metadata file.
The New Experience's metadata-download process requires a value to be present in the Issuer field; when the Issuer field is empty, the download fails.
Resolution 1:
Most SAML configurations require a value in the Issuer field anyway, since it maps to the service provider's Entity ID (or a similar identifier). If there is no requirement for a value in this environment, use one of the following options:
- Download the metadata file from the Advanced interface for the realm instead, on the Post Authentication tab — this path does not require an Issuer value.
- If setting a value doesn't cause problems with the service provider, add a value to the Issuer field under the realm's SAML properties. This also allows the metadata to download successfully from the New Experience interface.
The screenshot below shows the IdP Issuer field under SAML Assertion in the realm's SAML properties.
Once a value is present in this field, the metadata download from the New Experience interface completes normally.
Cause 2: Classic Interface Metadata Generation Fails (Missing Required Fields)
Applies to all versions.
Attempting to generate the metadata for a SAML realm from the Classic interface's SAML properties page can fail with an inline error:
The required fields to generate the metadata are not properly filled out.
Resolution 2:
Verify all of the following on the realm's SAML properties page:
- The Domain field is filled in.
- The WSFed/SAML Issuer field has a value.
- A signing certificate is properly selected.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.