cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

SAML2 configuration not working with Web Dispatcher

saar_koren
Explorer
0 Kudos
2,054

Hello,


We have a new S/4HANA 2020 system that we configured to use SAML2 with Microsoft ADFS as the identity provider. We have other ABAP systems in this landscape that already work with SAML2 and we configured this system in the same way. The only difference is that this system has a Web Dispatcher built in to the ASCS.

Currently the SAML2 configuration does not work correctly, and we are not sure why. We ran a trace, but found no errors, although we don't see that the SAML2 flow completed either. One specific line in the trace that raised suspicion is:

SAML20 SP (client 400 😞 calculate_acs_url ef_url: https://server FQDN:44300/sap/saml2/sp/acs/400

44300 is the ICM port, but all other requests in the trace use 443, which is the Web Dispatcher port.

I have attached the SAML2 trace and the metadata.xml file.

Thank you,
Saar

Accepted Solutions (0)

Answers (1)

Answers (1)

Isaias_SAP
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hello Saar,

Have you downloaded the SAML metadata through the Web Dispatcher?

If not, reconfigure SAML and download the metadata through the Web Dispatcher (SAP KBA 2326063).

Regards,

Isaías

saar_koren
Explorer
0 Kudos

Hello Isaías,

I configured SAML and downloaded the metadata while connected through the Web Dispatcher.

However, if you look at the trace that I have attached, you will see that the assertion consumer service is accessed with the ICM port instead of the Web Dispatcher port. This is my main suspicion, though I am not sure why it happens.

Thanks,

Saar