Symptom
- You have configured SAML SSO between HANA and an IdP of your choice.
- The SAML assertion forwards the user to the IdP where it is successfully authenticated.
- However the user is then forwarded to http://<hostname>:80<instance_number>/sap/hana/xs/saml/login.xscfunc where a generic error is displayed.
- You check the xsengine trace file and find this error:
"Assertion authentication for user failed with reason: NameID format is not supported(StatusCode: , StatusMessage: )"
Read more...
Environment
- SAP HANA 1.0 SPS12
- SAP HANA 2.0
- XS Engine Classic
Product
SAP HANA 1.0, platform edition ; SAP HANA, platform edition 2.0
Keywords
HANA, SAML, SSO, NameID, external identity, WindowsDomainQualifiedName, unspecified, emailAddress , KBA , HAN-DB-SEC , SAP HANA Security & User Management , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.