Andrew Wood
Articles
-
OIDC Scopes vs Claims
Version Affected: All Description: How do OIDC Scopes relate to Claims Cause: FAQ Resolution: There is a direct relationship between scopes and claims. We follow the specs outlined here ...
-
SAML signing cert export format issue
Version Affected: All Description: After exporting the signing cert from the PostAuth tab of a SAML realm to import into an SP, the SP throws an "Invalid Cert" error. Google G Suite is one su...
-
Transformation Engine not working as expected with SecurePortal / TSSO
Version Affected: All Description: A realm using the transformation engine works perfectly fine and then, once Transparent SSO or SecurePortal is enabled, it seems to stop working or become inte...
-
AD LDS over SSL failing with "Error Retrieving Contact Information"
Version Affected: All Description: When trying to connect to AD LDS using SSL, the connection fails and the users see "Invalid User" if ADLDS is the membership provider.If using ADLDS as an addi...
-
Error: Sequence contains more than one matching element
Version Affected: 21.04, 22.02 Description: Some Users are missing their Mobile devices after upgrading. The Error log shows System.InvalidOperationException: Sequence contains more than one mat...
-
OIDC configuration with Tableau
Version Affected: All Description: Tableu's documentation says "If your OpenID Connect IdP requires a specific authentication context, you can specify a list of essential and voluntary ACR value...
-
Username & Password login with New Experience Realms
Version Affected: 20.06+ Description: When setting a Policy in the new experience, the workflow options are different compared to the classic realms. For example, Username & Password is not an o...
-
New Experience realms stop working on secondary servers
Version Affected: 23.07 and 24.04 Description: New Experience realms stop working on secondary servers in 23.07 and 24.04 due to an issue with the password replication from the Primary to the Sec...
-
How to connect to a specific AD Site
Version Affected: AllDescription: When using Active Directory as a Datastore, if the domain name doesn't match the domain that the IdP is joined to, SecureAuth performs a SRV lookup for your conn...
-
How to troubleshoot Kerberos SPN issues
Version Affected: All Description: Our standard deployment can use Windows Authentication, sometimes known as Windows SSO in order to allow a User of a domain joined machine to log in with their...