SAP Knowledge Base Article - Preview

3328969 - SAML SSO connection to HANA not working

Symptom

You have tried to establish a secure connection between your applications and HANA on-premise DB with SAML SSO. Every step seems correct, but you still receive 403 forbidden error.

You may not even able to access your SAP HANA XS Admin Page any more due to 403 forbidden or errors like "unknown error" prompted at the page.

After enabled authentication debug trace on DB side, you may see error messages in xsengine log or indexserver log(xsengine set as embedded mode) like:

xsengine_your_host_name.30007.xxx.trc
============================
[12345]\{12345\}[-1/-1] 9999-99-99 00:00:00.0000 d XSRequestHandler RequestHandler.cpp(00332) : dispatching '/sap/hana/xs/saml/login.xscfunc'
...
[12345]\{12345\}[-1/-1] 9999-99-99 00:00:00.0000 d XSRequestHandler RequestHandler.cpp(00865) : Sent response with status 403 (rc=1189) 


Read more...

Environment

  • SAP HANA platform edition, 1.0
  • SAP HANA platform edition, 2.0

Product

SAP HANA 1.0, platform edition ; SAP HANA, platform edition 2.0

Keywords

SAC, live data connection, HANA, SAML, SSO, CORS, runtime_configuration, standard packages, 403 forbidden , KBA , HAN-DB-SEC , SAP HANA Security & User Management , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.