SAP Knowledge Base Article - Preview

3230509 - Service Provider (SP) Initiated login fails with error "The NameIDPolicy format agreement between SP and IdP is not met!"

Symptom

  • In the Identity Authentication (IAS) Troubleshooting Logs the error is found:

    Error SAML2Response received. Details: The NameIDPolicy format agreement between SP and IdP is not met!

  • IAS has Name ID Policy set as 
    Email
    Name ID format urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress is always sent.

  • You can see in the SAML trace the mismatch of Name ID format :

    <NameIDPolicy Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" />
    ....

    <ns2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"><Service Provider></ns2:Issuer> 


Read more...

Environment

Identity Authentication

Product

Identity Authentication 1.0

Keywords

corp Name identifier unique , KBA , BC-IAM-IDS , Identity Authentication Service , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.