Hi all,
after a long fight, I was able to set up SAML SSO for ISVG Identity Manager through Azure AD. What I still cannot figure out is how to login interactively using login and password when Trust association on Securit Domain is on. Is that even possible? With TAI turned off, everything works fine and I can login using login/pass. If I turn Trust association on and SSO starts working, I can still access the login form on URL https://server_url/itim/console/jsp/logon/Login.jsp, but after submitting form, I get 401 unauthorized all the time. Which is OK if the login/pass don't match, but when they DO match, I even get LTPA token (I can see it in cookies), but it is not accepted, 401 error is returned and I am redirected to the IdP page.
Can someone please tell me if this combined scenario supposed to be working and if so, where to look or what to look for? Thanks.
------------------------------
Pavel Koza
------------------------------