IDP SSO Questions

D
DavidF
Beam Suntory, Inc.

Hey Folks,

We are trying to setup SAML IDP using Azure ADFS, however we are getting a message saying "Invalid SAML 2.0 message. Response needs to be signed"

However we have uploaded our most recent metadata file and we feel we have mapped our groups, names etc correctly and our response looks like it contains the correct information  so we are a bit stumped. 

Can anyone shed any light on what could be causing this.

Thanks David 

5 years ago
SOTI MobiControl
ANSWERS
D
DDMOD@SOTI
5 years ago

Hi David,

Is this a new installation or are you upgrading from an older version of MobiControl?
Was SSO working before?

I would like you to re-do the configurations and export the XML file again and import back into where the SSO was configured.

Kindly share the outcome, once you try this.

Regards,

D
DavidF
5 years ago

Hi,

This is a new install and we have never had SSO working before. We have only recently started working with SOTi and wanted to configure it using Azure ADFS groups.

Just to be clear do you mean redownload the SOTi Certificate and Metadata and reinsert it into our SSO before exporting the the ADFS metadata back onto soti? 

should we configure the additional information section before or after the download?

Thanks David 

J
JVMOD@SOTI
5 years ago

Hello DavidF,

Thank you for your response, do you have users assigned to a group named as "groups"?

Also, how is your AD set-up? is it hosted on cloud or are you using local server?

Thanks and Regards,

D
DavidF
5 years ago

Hi,

We have a group named withiin the end point but the group identifier within the xml is called groups. we are using a cloud based Azure ADFS 

here is an excerpt from the SAML response

<Attribute Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/groups">
<AttributeValue>XXXXXXXXXXX</AttributeValue>
</Attribute>
 
Thanks David 
J
JVMOD@SOTI
5 years ago

Hello DavidF,

Thank you for your response, I would like you to create a support case(click here) or call SOTI Support team(click here) to raise this issue as we may need to look into your instance. 

To provide you with a heads up, our support team will investigate the issue further and if required they can create development ticket as well. 

Also, if this post has helped you in solving your inquiry, I would request you to mark the particular comment as "is solution", so others may benefit from this information.

Regards,