SAP Knowledge Base Article - Preview

3781637 - SAML Authentication Failures For SSO Login Fails with http 401 (unauthorized) due to signature validation error

Symptom

  • SAML login requests fail with HTTP 401 errors (HTTP Status 401 – Unauthorized).
  • Logs show SignatureException with message: "Unable to evaluate key against signature".
    Exception:
    org.opensaml.xmlsec.signature.support.SignatureException
    Message:
    Unable to evaluate key against signature
 
  • SAML assertion validation logs show NotBefore/NotOnOrAfter checks evaluated against skewed time.
  • System clock drift observed (>30 minutes).
  • Application pods report "No route to host" when connecting to internal ZooKeeper nodes.
  • Affected ZooKeeper endpoint observed: zookeeper-2.zookeeper:2181.
    Stacktrace:
    org.opensaml.xmlsec.signature.support.impl.provider.ApacheSantuarioSignatureValidationProviderImpl.validate
    org.opensaml.xmlsec.signature.support.SignatureValidator.validate
    org.opensaml.xmlsec.signature.support.impl.BaseSignatureTrustEngine.verifySignature
    org.opensaml.xmlsec.signature.support.impl.ExplicitKeySignatureTrustEngine.doValidate
    org.opensaml.xmlsec.signature.support.impl.BaseSignatureTrustEngine.validate
 


Read more...

Environment

SAP Commerce Cloud 2211-jdk21

Product

SAP Commerce Cloud all versions

Keywords

saml, http 401, unauthorized, signatureexception, signature validation, opensaml, spring security saml, clock skew, notonorafter, notbefore, metadata, certificate, saml trace, storefront , KBA , CEC-SCC-CLA-ENV-EMG , Environment Management , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.