Symptom
- All or specific users fail to log on with SAML authentication
- Error message "Http status 500-Internal Server Error" after logging in to the Identity Provider (IDP) page.
- The following error appears on the BI launchpad Webtrace:
doUserLogon(): failed to logon, logonCred=user:UserEmail,method:password,auth=secEnterprise,aps=CMS:6400 - On the SpringSAML logs show the same User email as NameID attribute is coming back from OKTA in the AuthNResponse as:
<NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">UserEmail</NameID> - Opening the user properties on CMC, notice that the user´s email alias does not match the email returned on the logs.
Read more...
Environment
- SAP BusinessObjects Business Intelligence platform 4.x
- SAML SSO authentication
Keywords
SSO, http 500, internal server error, IDP, BI, email alias, SAML, NameID, user , KBA , BI-BIP-AUT , Authentication, ActiveDirectory, LDAP, SSO, Vintela , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview