Troubleshooting: SP-Initiated SAML Response Cannot Be Signed

Follow
    Applies to:
Deployment model:
  • On Premises
  • Version Affected: All
     
     

    Overview

    Signing in to a Service Provider (SP) through SP-initiated SAML fails, and the realm's log shows an exception ending in MFC.WebApp.SecureAuth.SAML20SPInit.CreateSAMLResponse, originating from X509Certificate2.get_PrivateKey().

     

    Cause

    The realm cannot access or use the private key it needs to sign the SAML response for the SP. This is most often a certificate configuration issue, but in an environment with more than one SecureAuth appliance it can also be caused by inconsistent realm or load-balancing configuration between the servers.

     

    Resolution

    Check each of the following:

    1. Confirm the certificate configured on the SecureAuth realm matches the certificate the Service Provider expects.
    2. Confirm the certificate's permissions allow the Network Service group to read it.
    3. If this environment has 2 or more SecureAuth appliances, also check:
      • The load balancer is set to persistent (sticky) load balancing, not round-robin — otherwise requests for the same login can alternate between servers mid-flow and get confused.
      • The Forms Auth/SSO Token settings are configured the same way on the realm across every appliance.
      • Every appliance has the correct certificate selected for that realm.

     
     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.