Symptom
If integrating IAS as a custom Identity Provider (IDP), ensure to provide relevant Identity Authentication Service (IAS) screenshots and har. file to facilitate effective troubleshooting processes.
- Screenshots
- har. file
"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."
Environment
- SAP Datasphere
- SAP Identity Authentication Service
Resolution
Part 1: Screenshot of your IAS application configuration information.
Provides a documentation with the following screenshots in case:
-
Self-defined Attributes:
- Subject Name Identifier:
- Default Name ID Format
- Conditional Authentication:
Part 2: Network trace when SSO errors occur in Datasphere.
Perform the following steps in Datasphere to record the network trace and then upload to the case:
-
Once you get the verification URL in Datasphere, open a new InPrivate window
-
Open the development tools (F12) -> Network tab
-
Past the URL in InPrivate window
-
Enter the credentials of custom IDP in InPrivate window
-
After the error occurs, download the network trace and attach it to the case.
There is also a troubleshooting KBA, you may take a look at it as well.
0002487567 - Troubleshooting SAML assertions when configuring SAML SSO in SAP Analytics Cloud (SAC)
(Although this KBA mentions SAC, it also works for Datasphere).
See Also
Keywords
Identity Authentication Service, Identity Provider, Service Provider, DS, IDP, SP, SSO, SAC , KBA , DS-SEC-AUTN , Authentication: SSO/SAML, OAuth Client , Problem
Product
Attachments
| Pasted image.png |
| Pasted image.png |
SAP Knowledge Base Article - Public