Skip to main content

Hi all ,

I have searched the internet high and low regarding this issue but found no help. So I am posing the question and hopefully there are some answers to this. I am working on enabling single sign-on with my university's Identity Provider.  

I am using eduPersonPrincipalName as Attribute Name and urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified as Name ID Format.

The login passed on the Identity Provider side but when they redirected it to my salesforce domain, the SSO error page shows up, saying "We can't log you in because of an issue with single sign-on. Contact your Salesforce admin for help." I don't get why Salesforce isn't accepting my IdP logins.  I am asking if there are other places I need to configure? Yes, I have checked SAML Enabled and Federation ID aren't the issue here since I am using Username for SAML Identity Type. My IdP told me that they are not seeing any errors on their side and the attributes passed perfectly. So how do I configure my salesforce single sign-on settings to allow my IdP to pass through the login process? 

 

The SAML response shows that all the check-ins are "OK" but still unable to map the subject to a salesforce user, that's strange. 

 

#Security #SAML Single Sign On #SingleSignOn #Authentication #Integration 

 

Single Sign On Error- using eduPersonPrincipalName as attribute name

8 risposte
0/9000