Version Affected: All
Overview
A user with a Windows Desktop Single Sign-On (SSO) realm is stopped for second-factor authentication after entering the correct credentials, and receives the error "SecureAuth is unable to process WS-Federation posts at this time. Review debug logs and configuration."
Cause
The certificate the realm uses to sign WS-Federation responses does not have the correct Read permission on its private key for the Authenticated Users and NETWORK SERVICE accounts.
Resolution
- In the SecureAuth Admin realm, go to the Post Auth tab and note which certificate is configured there.
- Open the Certificates console and browse to Certificates > Personal > Certificates.
- Right-click the certificate noted in step 1 and select All Tasks > Manage Private Keys.
- Confirm that both Authenticated Users (domain group) and NETWORK SERVICE (local group) have at least Read authority. Grant Read to whichever one is missing it.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.