SAML authentication is rejected due to metadata mismatch
Applies to
- System Manager 9.7
- Microsoft ADFS
Issue
- Unable to authenticate via SAML to System Manager because the IdP metadata does not contain an email address
- The
/mroot/etc/shibboleth/shibd.log
contains the following errors:
[kern_shibd:info:9583] ERROR OpenSAML.MetadataProvider.XML : metadata instance failed manual validation checking: EmailAddress must have TextContent
[kern_shibd:info:9583] WARN Shibboleth.SessionInitiator.SAML2 [1] [default]: unable to locate metadata for provider (https://sts.iconplc.com/adfs/services/trust)
Unknown or Unusable Identity Provider The identity provider supplying your login credentials is not authorized for use with this service or does not support the necessary capabilities