Symptom
We are using Keycloack as a SAML-system and always getting an error during the SSO-login.
Resolution
Please check within the Keycloack attribute mapper, if there is an automatic attribute "role list". If yes, please remove this attribute as this attribute is sending the user roles instead of one attribute with different values, as different attributes with one value and all attributes have the same name.
Keywords
sap-signavio, single-sign-on, keycloack, idp, attribute-mapping, role-list , KBA , BPI-SIG-CA-SEC-SAM , SAML 2.0 for SAP Signavio , Problem
Product
SAP Signavio Process Manager all versions