IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  DPWAP0011E Error while configuring ADFS with ISVA 10.0.6

    Posted Fri August 11, 2023 11:41 AM

    Hello Everyone,

    Currently we are integrating ADFS with ISVA using SAML protocol. We are referring the below documentation from IBM Community: 

    https://community.ibm.com/community/user/security/blogs/haan-ming-lim1/2020/09/07/adfs-30-step-by-step-guide-federation-with-ibm-sec  

    We have created the federation entry for ADFS in Federations. But while creating federation on WEBSEAL, we are facing one issue related to junction creation.

    ADFS Error


     version of ISVA is 10.0.6 

    for troubleshooting we are using this document https://www.ibm.com/support/pages/node/885700

    Please guide us on this



    ------------------------------
    shivsantosh patil
    ------------------------------



  • 2.  RE: DPWAP0011E Error while configuring ADFS with ISVA 10.0.6

    Posted Sun August 13, 2023 05:27 PM

    Unfortunately what you have included below is only a part of the error message and doesn't really explain what is going wrong. 

     

    Are you able to check to ensure that the rest of the error message hasn't scrolled off the dialog box, and also check the WebSEAL log file for additional information.

     

    Thanks.

     

    Scott A. Exton
    Senior Software Engineer
    Chief Programmer - IBM Security Verify Access

    IBM Master Inventor

    cid4122760825*<a href=image002.png@01D85F83.85516C50">

     

     






  • 3.  RE: DPWAP0011E Error while configuring ADFS with ISVA 10.0.6

    Posted Wed August 16, 2023 09:29 AM

    Hello Scott,

    Thank you for your reply.

     We are able to create the junction via IP instead of hostname but now we are getting the Authorization error. Does it require any ACLs to be attached to this junction created for ADFS?
    Attaching images of forbidden error and request.log file: 

      



    ------------------------------
    shivsantosh patil
    ------------------------------



  • 4.  RE: DPWAP0011E Error while configuring ADFS with ISVA 10.0.6

    Posted Wed August 16, 2023 05:49 PM

    Shivsantosh,

     

    So, it sounds like you had a DNS issue in your environment.  As far as the ACL goes, when accessing the junction for a normal GET request the 'r' bit is required for the user who is accessing the resource.

     

     

    Scott A. Exton
    Senior Software Engineer
    Chief Programmer - IBM Security Verify Access

    IBM Master Inventor

    cid4122760825*<a href=image002.png@01D85F83.85516C50">

     






  • 5.  RE: DPWAP0011E Error while configuring ADFS with ISVA 10.0.6

    Posted Thu August 17, 2023 07:40 AM

    Hello Scott,

    we have attached ACL also and assigned Read permission also but still facing the same issue.

     



    ------------------------------
    shivsantosh patil
    ------------------------------