<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAML SSO Problem using SUN Access Manager in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/saml-sso-problem-using-sun-access-manager/m-p/3542248#M852164</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got some problems when testing the SAML SSO functionality according to the document [http://developers.sun.com/identity/reference/techart/sso.html|http://developers.sun.com/identity/reference/techart/sso.html]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Identity Provider: SUN Access Manager 7.1 under Windows 2003&lt;/P&gt;&lt;P&gt;Service provider: SAP JAVA WAS 6.40 SP19&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After both sides configuration I tried the SSO using the URL as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="http://sunam.test.de:8080/amserver/SAMLAwareServlet?TARGET=http://grcsuite.test.de:50000/useradmin/userAdminServlet" target="test_blank"&gt;http://sunam.test.de:8080/amserver/SAMLAwareServlet?TARGET=http://grcsuite.test.de:50000/useradmin/userAdminServlet&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the Virtual Administrator I had already configured SAMLLoginModule at the 1.st  place with the flag SUFFICIENT in the Basic template. After successfully authenticated to the Access Manager I was redirevted to the following URL where unwanted logon window (to SAP J2EE Engine) is shown again:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="http://grcsuite.test.de:50000/logon/logonServlet?redirectURL=%2Fuseradmin%2FuserAdminServlet%3FSAMLart%3DAAESqssSVZw4qJyKxSl1v50iaxCefD2mKLU6HZUPKHLfu9txxFn6ZDAx" target="test_blank"&gt;http://grcsuite.test.de:50000/logon/logonServlet?redirectURL=%2Fuseradmin%2FuserAdminServlet%3FSAMLart%3DAAESqssSVZw4qJyKxSl1v50iaxCefD2mKLU6HZUPKHLfu9txxFn6ZDAx&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anybody give me some hints, why the SSO fails or how to debug the problem? If needed, I could provide more info about my system configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THX,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Mar 2008 16:16:54 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-03-14T16:16:54Z</dc:date>
    <item>
      <title>SAML SSO Problem using SUN Access Manager</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/saml-sso-problem-using-sun-access-manager/m-p/3542248#M852164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got some problems when testing the SAML SSO functionality according to the document [http://developers.sun.com/identity/reference/techart/sso.html|http://developers.sun.com/identity/reference/techart/sso.html]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Identity Provider: SUN Access Manager 7.1 under Windows 2003&lt;/P&gt;&lt;P&gt;Service provider: SAP JAVA WAS 6.40 SP19&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After both sides configuration I tried the SSO using the URL as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="http://sunam.test.de:8080/amserver/SAMLAwareServlet?TARGET=http://grcsuite.test.de:50000/useradmin/userAdminServlet" target="test_blank"&gt;http://sunam.test.de:8080/amserver/SAMLAwareServlet?TARGET=http://grcsuite.test.de:50000/useradmin/userAdminServlet&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the Virtual Administrator I had already configured SAMLLoginModule at the 1.st  place with the flag SUFFICIENT in the Basic template. After successfully authenticated to the Access Manager I was redirevted to the following URL where unwanted logon window (to SAP J2EE Engine) is shown again:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="http://grcsuite.test.de:50000/logon/logonServlet?redirectURL=%2Fuseradmin%2FuserAdminServlet%3FSAMLart%3DAAESqssSVZw4qJyKxSl1v50iaxCefD2mKLU6HZUPKHLfu9txxFn6ZDAx" target="test_blank"&gt;http://grcsuite.test.de:50000/logon/logonServlet?redirectURL=%2Fuseradmin%2FuserAdminServlet%3FSAMLart%3DAAESqssSVZw4qJyKxSl1v50iaxCefD2mKLU6HZUPKHLfu9txxFn6ZDAx&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anybody give me some hints, why the SSO fails or how to debug the problem? If needed, I could provide more info about my system configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THX,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2008 16:16:54 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/saml-sso-problem-using-sun-access-manager/m-p/3542248#M852164</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-03-14T16:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: SAML SSO Problem using SUN Access Manager</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/saml-sso-problem-using-sun-access-manager/m-p/3542249#M852165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I traced that Sun AM had sent the SAML assertion to SAP, and according to the assertion I would guess the problem is regarding the NameIdentifier. Intentially when I created SAP as the trusted partner in Sun AM I had configured to use the class provided from [http://developers.sun.com/identity/reference/techart/sso.html|http://developers.sun.com/identity/reference/techart/sso.html]: to generate the required NameIdentifier, which in this case should be &lt;STRONG&gt;binwang&lt;/STRONG&gt; instead of &lt;STRONG&gt;id=binwang,ou=user,dc=sample,dc=com&lt;/STRONG&gt;.Any idea how to solve this problem here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;saml:Assertion  xmlns:saml="urn:oasis:names:tc:SAML:1.0:assertion" MajorVersion="1" MinorVersion="0" AssertionID="&lt;/P&gt;&lt;P&gt;sba84ca9dad01f929deba8796d887bd3bfaf8972501" Issuer="sunam.test.de:8080" IssueInstant="2008-03-16T19:08:08Z"&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;       &amp;lt;saml:Conditions  NotBefore="2008-03-16T19:05:08Z" NotOnOrAfter="2008-03-16T19:15:08Z" &amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;       &amp;lt;/saml:Conditions&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;       &amp;lt;saml:AuthenticationStatement AuthenticationMethod="urn:com:sun:identity:DataStore"                                                                                &lt;/P&gt;&lt;P&gt;AuthenticationInstant="2008-03-16T19:08:06Z"&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                 &amp;lt;saml:Subject&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                        &amp;lt;saml:NameIdentifier NameQualifier="dc=sample,dc=com"&amp;gt;id=binwang,ou=user,dc=sample,dc=com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                        &amp;lt;/saml:NameIdentifier&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                        &amp;lt;saml:SubjectConfirmation&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                                     &amp;lt;saml:ConfirmationMethod&amp;gt;urn:oasis:names:tc:SAML:1.0:cm:artifact-01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                                     &amp;lt;/saml:ConfirmationMethod&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                        &amp;lt;/saml:SubjectConfirmation&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                 &amp;lt;/saml:Subject&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                 &amp;lt;saml:SubjectLocality  IPAddress="192.168.164.130" /&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;           &amp;lt;/saml:AuthenticationStatement&amp;gt;+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/saml:Assertion&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Mar 2008 16:32:16 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/saml-sso-problem-using-sun-access-manager/m-p/3542249#M852165</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-03-17T16:32:16Z</dc:date>
    </item>
  </channel>
</rss>

