WebSphere Application Server & Liberty

WebSphere Application Server & Liberty

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  SAML SSO implementation with Websphere and IBM Content navigator

    Posted Thu August 17, 2023 10:18 AM

    Dear ALL,

    I need help to configure ICN with SAML and IDP is VMWARE Indentity Manager



    ------------------------------
    filenet MOF
    ------------------------------


  • 2.  RE: SAML SSO implementation with Websphere and IBM Content navigator

    Posted Fri August 18, 2023 04:06 AM

    Hi, You did not provide any information of your issue,  Here is the documentation to use SAML with SSO.

    Brian



    ------------------------------
    Brian S Paskin
    Sr. Technology Engineer
    IBM Cloud Engineering
    ------------------------------



  • 3.  RE: SAML SSO implementation with Websphere and IBM Content navigator

    Posted Mon August 21, 2023 01:41 AM

    Hi,

    Thanks for the reply.

    I am following the below article from IBM to implement the SAML

    https://www.ibm.com/support/pages/configuring-ibm-content-navigator-203-and-30x-using-security-assertion-markup-language-saml-single-sign-websphere-application-server

    For this I am having issues with the SAML as I have successfully done all the steps like for IDP initiated SAML request but I am facing below issue
    1- When I hit on Navigator URL its going fine to IDP login page
    2- but when I click the Navigator application icon in IDP application, it goes again to the same page like a loop and Navigator destop is not appearing.

    Where I am doing wrong ?

    Regards 



    ------------------------------
    filenet MOF
    ------------------------------



  • 4.  RE: SAML SSO implementation with Websphere and IBM Content navigator

    Posted Mon August 21, 2023 05:35 AM

    Hi, if the IdP is returning to tWAS and then going back to the IdP then you have a misconfiguration in your steps.  You should check to make sure the properties are correct and check the logs for errors.  

    If the IdP is just forwarding to itself it may be a misconfiguration on the IdP side.

    Brian



    ------------------------------
    Brian S Paskin
    Sr. Technology Engineer
    IBM Cloud Engineering
    ------------------------------



  • 5.  RE: SAML SSO implementation with Websphere and IBM Content navigator

    Posted Mon August 21, 2023 05:48 AM

    Hi Brian,

    Thanks for your reply.

    The ideal steps should be like User should login into the IDP app and my ICN app should be triggered from IDP and user should see the ICN Desktop as per the authurization.

    I have done the steps which mentioned in IBM article and I have done all the IDP part as well
    I export the sp data and import it to IDP as well
    now I am getting below error


    "[8/21/23 13:40:25:860 GST] 000000bc ACSTrustAssoc >  createTAIErrorResult(req[com.ibm.ws.webcontainer.srt.SRTServletRequest], res[com.ibm.ws.webcontainer.srt.SRTServletResponse], msg[CWWSS8017E: Authentication Error: Single-Sign-on cookie is not present or could not be verified. Please login to the SAML Identity Provider, and try again.], before[false]) Entry"

    Regards,



    ------------------------------
    filenet MOF
    ------------------------------



  • 6.  RE: SAML SSO implementation with Websphere and IBM Content navigator

    Posted Mon August 21, 2023 06:45 AM

    Please see these explanations of the error and how to correct the issue:

    https://www.ibm.com/support/pages/node/277989/#CWWSS8017E

    Brian



    ------------------------------
    Brian S Paskin
    Sr. Technology Engineer
    IBM Cloud Engineering
    ------------------------------