ONTAP SAML setup fails when ADFS server has a self-signed certificate
Applies to
- ONTAP 9.9+
Issue
- ONTAP fails to download federation metadata because it does not trust the ADFS server
- URL for AD infrastructure has CA-signed certs, but the actual ADFS servers in the pool use self-signed certs
- Error on CLI with
saml-sp create
:-
Error: command failed: [Job 10695] Job failed: SAML job failed, Reason: Failed to download data from URL https://auth.corp.net/FederationMetadata/2007-06/FederationMetadata.xml.Reason: SSL peer certificate or SSH remote key was not OK : SSL certificate problem: unable to get local issuer certificate.
The system encountered an error at Tue Feb 14 17:58:10 2023 at https://corpadfs3.dept.loc.corp.net/saml-sp/SAML2/POST
Message was signed, but signature could not be verified.
-