SAP Knowledge Base Article - Preview

3570866 - Mismatched SAML Authentication Contexts (AuthnContext) Between Trusted Providers and Identity Provider (IDP)

Symptom

  • SAML authentication fails due to mismatched AuthnContext values.

  • The error indicates that trusted providers (Service Providers/SPs) are configured with AuthnContextClassRef = urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified , while the IDP uses PasswordProtectedTransport.

  • Example SAML AuthnRequest snippet from the SP:
    <samlp:RequestedAuthnContext>
      <saml:AuthnContextClassRef>
        urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified
      </saml:AuthnContextClassRef>
    </samlp:RequestedAuthnContext>


Read more...

Environment

SAP ABAP NetWeaver Application Server

Product

SAP NetWeaver Application Server all versions

Keywords

SAML2, authentication context, SAML2_AUTH_CTX, Security , KBA , BC-SEC-LGN-SML , SAML 2.0 for ABAP , BC-SEC-LGN , Authentication , Known Error

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.