Maximo

 View Only
  • 1.  Maximo SAML redirecting to You cannot login at this time. Contact the system administrator

    Posted Thu April 27, 2023 05:11 PM

    Hi,

    I have 1 server and 5 cluster each with one jvm. I have SSL configured. I have SAML configured with Azure AD as the IDP.  Once we login to Maximo, instead of redirecting to Maximo Welcome page, It redirects to Maximo loginerror page.
    https://hostname:443/maximo/webclient/login/loginerror.jsp?group=system&key=NoLogin
    you cannot login at this time. Contact the system administrator.
     There are no error in System out and SystemErr logs. 
    The system property mxe.enableConcurrentCheck is also set to 0.

    Any leads to fix the issue will be helpful.

    Regards,
    Chhavi



    ------------------------------
    Chhavi Poddar
    ------------------------------

    #MaximoEAM
    #Maximo


  • 2.  RE: Maximo SAML redirecting to You cannot login at this time. Contact the system administrator

    Posted Fri April 28, 2023 02:35 PM

    SAML is similar to LDAP where you need to have the security constraints enabled in the various web.xml files. Can you confirm that you have these configured? One of the causes of the nologin is a misconfiguration where you haven't set those up. We document it here: https://www.ibm.com/docs/en/mfci/7.6.2?topic=security-configuring-assertion-markup-language-saml

    Normally with SAML your login will be an email address. I would confirm on the MAXUSER table that the loginid matches what will be coming from the Identity Provider. 



    ------------------------------
    Steven Shull
    ------------------------------



  • 3.  RE: Maximo SAML redirecting to You cannot login at this time. Contact the system administrator

    Posted Fri April 28, 2023 10:44 PM

    Hi Steven,

    Thanks for your reply!
    I have configured AppServersecurity as 1 in all the web.xml files as per the link and also the other steps mentioned in the below link.
    https://www.ibm.com/docs/en/mfci/7.6.2?topic=security-configuring-assertion-markup-language-saml

    I have also updated the loginid in MAXUSER table as the email address which is coming from IDP but still I am getting the error .
    You cannot login at this time. Contact the system administrator.

    Regards,
    Chhavi




    ------------------------------
    Chhavi Poddar
    ------------------------------



  • 4.  RE: Maximo SAML redirecting to You cannot login at this time. Contact the system administrator

    Posted Sat April 29, 2023 09:27 AM

    I'd recommend opening a support ticket with IBM to help you get to the finish line. Reviewing your exact WebSphere configuration and logs at this point is important and you won't want to post those here. If you want to try and resolve yourself, there are some helpful debugging steps here:
    https://www.ibm.com/support/pages/troubleshoot-saml-web-sso-websphere-traditional



    ------------------------------
    Steven Shull
    ------------------------------



  • 5.  RE: Maximo SAML redirecting to You cannot login at this time. Contact the system administrator

    Posted Wed May 03, 2023 09:31 AM
    When you use SAML, a token is created and verified by the IdP and then passed to IBM® Maximo® Asset Management. This authentication mechanism is supported in WebSphere Application Server by a Trust Association Interceptor (TAI).


    ------------------------------
    Amelia Mia
    ------------------------------



  • 6.  RE: Maximo SAML redirecting to You cannot login at this time. Contact the system administrator

    Posted 20 days ago
    Edited by tena lena 19 days ago

    Similar to LDAP, SAML requires that the security restrictions be enabled in each of the different web.xml files. Could you verify that these are configured? You might not have put things up, which is one of the setup errors that lead to the nologin. Here is where we record it: In this document, it's here the topic of security configuration assertion markup language Saml is discussed.



    ------------------------------
    tena lena
    ------------------------------