SAP Knowledge Base Article - Preview

3284030 - SAML SSO doesn't work for HANA XS apps due to missing "PSE stores for purpose SAML"

Symptom

SAML SSO doesn't work when you try to launch HANA xs apps, e.g. https://<host name>:43<instance number>/sap/bc/ina/service/v2/GetServerInfo 
Following information could be found in xsengine trace when you have enabled debug level trace.

alter system alter configuration ('global.ini','system') set
('trace','authentication') = 'debug',
('trace','crypto') = 'debug',
('trace','xsauthentication') = 'debug',
('trace','xsrequesthandler') = 'debug',
('trace','xssession') = 'debug',
('trace','xssamlservice') = 'debug'
with reconfigure; 

xsengine...trc
******

d Crypto           CatalogPSEStoreStorage.cpp(00228) : Returning 0 PSE store(s) for purpose SAML
...
i Crypto           PSEStoreManager.cpp(00166) : No PSE stores for purpose SAML found
...
d XSRequestHandler RequestHandler.cpp(00865) : Sent response with status 303 (rc=1457)

******


Read more...

Environment

  • HANA 1.0
  • HANA 2.0

Product

SAP Analytics Cloud all versions ; SAP HANA, platform edition all versions

Keywords

Single sign on, SAML, 303 , KBA , HAN-DB-SEC , SAP HANA Security & User Management , How To

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.