Skip to main content

#Single Sing-on토론 중인 항목 0개

I have completed all the steps in the Multi-factor Authentication and Single Sign-On Settings Superbadge but cannot pass the final challenge - Lightning Login and Salesforce Authenticator App. I can login as Brochane and connect the Salesforce Authenticator app. When I click to Enroll in Lightning Login I get a screen that says Approval Required, but nothing happens in my Salesforce authenticator app to request approval. I have disconnected and re-connected the app multiple times but nothing works. What else can I do to get this working and pass the challenge?

 

#Trailhead Challenges  #SF Authenticator  #Single Sing-on

답변 4개
  1. 2024년 2월 28일 오후 2:42

    I wasn't missing any steps. If anyone else gets stuck here, for some reason enabling the correct system permissions setting wasn't actually saving in my permission set. I tried saving another random permission and that seemed to register, so then I went and saved the specific permission for this badge and that time the saved worked. The classic turn it off, then turn it back on seemed to work here.

0/9000
Dilipan M (Equiniti) 님이 #SSO에 질문했습니다

My single sign on shows two different expiration date.

When I checked the SAML Single Sign On settings page in setup, for the field 'Identity Provider Certificate', It shows the following value 'CN=Microsoft Azure Federated SSO Certificate

Expiration: 4 Jul 2026 13:10:37 GMT'

 

I then opened the certificate itself, present on the field Request Signing Certificate, it says that the expiration date is in 2024.

 

Which is the true expiration date?

 

I checked with my Identity Provider team, they said it is 2026, but want to double check why it is showing 2024 in SF.

 

#SSO  #SSO Setup  #Single Sing-on  #Security  #Identity & Access Management

답변 1개
  1. Sushil Kumar (UKG) Forum Ambassador
    2024년 2월 21일 오전 11:23
    Those are two different types of certificate. Request signing certificate could be used by your IDP to verify the Auth N request coming from Service provider (which is Salesforce in this case). A lot of cases IDP may not verify this certificate. You can check with your IDP team if they use SF request signing certificate for auth N request(For SP initiated SSO). The second certificate is the IDP certificate which is provided by your IDP, when IDP posts SAML response, they sign response with that certificate, and then Salesforce can use certificate uploaded in SF to verify the response to make sure it’s coming from right source.
0/9000

Hi Folks,

One of our clients is planning to remove SSO from their ORG. I do not see any form of guide to remove SSO from an ORG. All I see are guides and trailheads on how to enable SSO and how to disable login from my domain. Any help is appreciated.

 

Thanks,

Sanam

 

#SSO #Single Sing-on

답변 3개
0/9000

i have followed all steps which asked to follow for Single Sign On implementation still i am not able to complete this topic. Need help on this to identify the issue. #Single Sing-on

답변 4개
  1. 2024년 1월 12일 오후 10:12

    Hi @Rahul Uttekar ,

     

    I launched new Playground and it worked !! Finally I can proceed further :)

    But still after requesting SAML response on Axiomsso site it was logging in my profile rather than other user's Id (whose Federation ID was mentioned ).

     

    https://trailhead.salesforce.com/trailblazer-community/feed/0D54S00000HDqbg

     

    I tried again, and again, and again and i found out that the problem was the My Domain. I started a new playground and didn't change the my domain and it worked

     

    https://trailhead.salesforce.com/trailblazer-community/feed/0D54S00000Cfn5XSAR

0/9000

I just set up SSO(Single Sign-on) in my DEV Sandbox with OKTA service provider. it worked perfectly for a while and after that, it stopped working. The error is "We can not log you in because of an issue with Single Sign-on, Contact your salesforce admin for help". the strange thing here is, I have checked with the OKTA team, in their logs it saying that successfully authenticated each time we try but it showing Error from SFDC login page. 

 

All configuration was perfect because it worked a while ago. I am testing in DEV Sandbox. any limitation on it. do you have any idea what causing this? 

0/9000