django-saml2-auth icon indicating copy to clipboard operation
django-saml2-auth copied to clipboard

Active Directory/SAML IDP can't process request

Open mrhatch opened this issue 8 years ago • 1 comments

Trying to access an Active Directory SAML IDP and they are unable to process my request. According to the IDP staff the problem is with the following line in the Request:

<ns1:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"

They want it to be: <ns1:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:unspecified"

or possibly removed from the request altogether as it is not an attribute they have ever used before. I am having to trust their word as this is my first SAML project and while it worked with Okta, it is erroring on their server.

mrhatch avatar May 09 '17 16:05 mrhatch

I was able to resolve the issue with this, it was not the nameid:format as was first suspected, rather it was the lack of an entityid in the saml. I was able to get it working by adding 'entityid' : 'https://server.host.com',

to the saml_settings in views.py

mrhatch avatar May 24 '17 12:05 mrhatch