[midPoint] "Unknown" username in SAML

Zico mailzico at gmail.com
Thu May 21 22:59:55 CEST 2020


Hello again!

I am trying to connect Midpoint authentication with Gluu Server SAML (
Shibboleth ).
I think I am almost there as now my "Midpoint" is forwarding to Gluu Server
for authentication.
After authentication, I am jumping into Midpoint again with below error.

I know I have two users ( one: administrator and another one: mohib ) in
Midpoint and both are SuperUser of course.

I can't understand why Midpoint unable to recognize UID I am forwarding
from Gluu Server.
In Gluu Server SAML assertion, I see that I am sending proper attributes (
including UID / Username ).

Any hint or suggestion please?

midpoint.log saying something like this:

2020-05-21 18:55:26,707 [] [http-nio-8080-exec-7] DEBUG
(com.evolveum.midpoint.web.security.filter.MidpointAuthFilter):
/auth/gluu/mySamlSso/SSO/alias/sp_midpoint at position 7 of 14 in
additional filter chain; firing Filter:
'MidpointSamlAuthenticationResponseFilter'
2020-05-21 18:55:26,708 [] [http-nio-8080-exec-7] DEBUG
(com.evolveum.midpoint.model.impl.security.SecurityHelper): Login failure
username=unknown user, channel=
http://midpoint.evolveum.com/xml/ns/public/model/channels-3#user: SAML
authentication module: web.security.flexAuth.saml.not.response
2020-05-21 18:55:26,708 [] [http-nio-8080-exec-7] INFO
(com.evolveum.midpoint.audit.log): 2020-05-21T18:55:26.708+0000
eid=1590087326708-0-2, et=CREATE_SESSION, es=REQUEST,
sid=C703BF94109A1711FFCB2B44710BCE12, rid=null, tid=1590087326708-0-1,
toid=null, hid=idm.gluu.org, nid=DefaultNode, raddr=127.0.0.1, I=null,
T=null, TO=null, D=[], ch=
http://midpoint.evolveum.com/xml/ns/public/model/channels-3#user,
o=FATAL_ERROR, p=unknown user, m=SAML authentication module:
web.security.flexAuth.saml.not.response



-- 
Best,
Zico
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200521/390dc692/attachment.htm>


More information about the midPoint mailing list