Version Affected: All
Overview
After authenticating on a realm such as a Security Assertion Markup Language (SAML) realm, the user reaches the Authorized page carrying the authentication token issued at login. This page either immediately throws a 404 error or sends the user back to the beginning of authentication on the SecureAuth.aspx page.
Cause
This happens when the authentication token is not valid immediately after reaching the Authorized page. In the realm's Custom Identity Consumer Token Settings, the Forms Authentication Domain field restricts the token so that it can only be used by pages under that domain. If this field is set to anything other than the correct company domain, the token is not usable by SecureAuth immediately after authentication, and the request fails.
Resolution
- In the Admin Console, go to Admin Realm > the affected realm > Workflow > Custom Identity Consumer > Token Settings.
- Check the Domain field under Forms Authentication settings.
- If it is set to anything other than the correct company domain, remove it. As a test, try removing it even if you are unsure whether it is the cause — this field only restricts the token, so removing it will not break the integration.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.