Enterprise Vault Single Sign-On fails to work as expected with IBM Security Access Manager (IBM Security Verify)

book

Article ID: 100050598

calendar_today

Updated On:

Description

Error Message

A dtrace of W3WP while attempting to Sign-On using SSO displays the following results:

 

46 17:28:39.701 [16280] (w3wp) <10480> EV-L {EVS}<br "droid="" "fira="" "helvetica="" -webkit-text-stroke-width:="" 0px;="" 14px;="" 255);="" 255,="" 2;="" 400;="" background-color:="" font-size:="" font-style:="" font-variant-caps:="" font-variant-ligatures:="" font-weight:="" initial;="" initial;"="" letter-spacing:="" neue",="" none;="" normal;="" orphans:="" oxygen,="" rgb(255,="" roboto,="" sans",="" sans-serif;="" segoe="" start;="" style="outline: none !important; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFont, " text-align:="" text-decoration-color:="" text-decoration-style:="" text-decoration-thickness:="" text-indent:="" text-transform:="" ubuntu,="" ui",="" white-space:="" widows:="" word-spacing:=""/> <br "droid="" "fira="" "helvetica="" -webkit-text-stroke-width:="" 0px;="" 14px;="" 255);="" 255,="" 2;="" 400;="" background-color:="" font-size:="" font-style:="" font-variant-caps:="" font-variant-ligatures:="" font-weight:="" initial;="" initial;"="" letter-spacing:="" neue",="" none;="" normal;="" orphans:="" oxygen,="" rgb(255,="" roboto,="" sans",="" sans-serif;="" segoe="" start;="" style="outline: none !important; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFont, " text-align:="" text-decoration-color:="" text-decoration-style:="" text-decoration-thickness:="" text-indent:="" text-transform:="" ubuntu,="" ui",="" white-space:="" widows:="" word-spacing:=""/> Certificate retrieved<br "droid="" "fira="" "helvetica="" -webkit-text-stroke-width:="" 0px;="" 14px;="" 255);="" 255,="" 2;="" 400;="" background-color:="" font-size:="" font-style:="" font-variant-caps:="" font-variant-ligatures:="" font-weight:="" initial;="" initial;"="" letter-spacing:="" neue",="" none;="" normal;="" orphans:="" oxygen,="" rgb(255,="" roboto,="" sans",="" sans-serif;="" segoe="" start;="" style="outline: none !important; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFont, " text-align:="" text-decoration-color:="" text-decoration-style:="" text-decoration-thickness:="" text-indent:="" text-transform:="" ubuntu,="" ui",="" white-space:="" widows:="" word-spacing:=""/> 47 17:28:39.701 [16280] (w3wp) <10480> EV-L {EVS}

Build the signed document
48 17:28:39.701 [16280] (w3wp) <10480> EV-L {EVS}

Signature verified with status - True
49 17:28:39.701 [16280] (w3wp) <10480> EV-L {EVS} SAML response signarure validated

50 17:28:39.701 [16280] (w3wp) <10480> EV-L {EVS}<br "droid="" "fira="" "helvetica="" -webkit-text-stroke-width:="" 0px;="" 14px;="" 255);="" 255,="" 2;="" 400;="" background-color:="" font-size:="" font-style:="" font-variant-caps:="" font-variant-ligatures:="" font-weight:="" initial;="" initial;"="" letter-spacing:="" neue",="" none;="" normal;="" orphans:="" oxygen,="" rgb(255,="" roboto,="" sans",="" sans-serif;="" segoe="" start;="" style="outline: none !important; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFont, " text-align:="" text-decoration-color:="" text-decoration-style:="" text-decoration-thickness:="" text-indent:="" text-transform:="" ubuntu,="" ui",="" white-space:="" widows:="" word-spacing:=""/> <br "droid="" "fira="" "helvetica="" -webkit-text-stroke-width:="" 0px;="" 14px;="" 255);="" 255,="" 2;="" 400;="" background-color:="" font-size:="" font-style:="" font-variant-caps:="" font-variant-ligatures:="" font-weight:="" initial;="" initial;"="" letter-spacing:="" neue",="" none;="" normal;="" orphans:="" oxygen,="" rgb(255,="" roboto,="" sans",="" sans-serif;="" segoe="" start;="" style="outline: none !important; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFont, " text-align:="" text-decoration-color:="" text-decoration-style:="" text-decoration-thickness:="" text-indent:="" text-transform:="" ubuntu,="" ui",="" white-space:="" widows:="" word-spacing:=""/> VerifyIssuerInSAMLResponse invoked<br "droid="" "fira="" "helvetica="" -webkit-text-stroke-width:="" 0px;="" 14px;="" 255);="" 255,="" 2;="" 400;="" background-color:="" font-size:="" font-style:="" font-variant-caps:="" font-variant-ligatures:="" font-weight:="" initial;="" initial;"="" letter-spacing:="" neue",="" none;="" normal;="" orphans:="" oxygen,="" rgb(255,="" roboto,="" sans",="" sans-serif;="" segoe="" start;="" style="outline: none !important; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFont, " text-align:="" text-decoration-color:="" text-decoration-style:="" text-decoration-thickness:="" text-indent:="" text-transform:="" ubuntu,="" ui",="" white-space:="" widows:="" word-spacing:=""/> 51 17:28:39.701 [16280] (w3wp) <10480> EV-L {EVS}

SAML response Issuer validation failed, as no Issuer value found in SAMLResponse

 

Cause

This issue can occur if the format of the Issuer tag is in an unexpected format. Enterprise Vault attempts to parse the decoded SAML response from the Identity provider.See below.

 

40 17:28:39.701 [16280] (w3wp) <10480> EV-L

{EVS} Decoded SAMLResponse from the IdentityProvider: | |

<saml:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">

 

Resolution

 

Enterprise Vault has acknowledged that the above-mentioned issue is present in the version(s) of the product(s) referenced in this article.

This issue is currently under investigation by Enterprise Vault. Pending the outcome of the investigation, this issue may be resolved by way of a cumulative hotfix or service pack in the current or future versions of the software. However, this particular issue is not currently scheduled for any release.  If you feel this issue has a direct business impact for you and your continued use of the product, please contact your Enterprise Vault Sales representative or the  Enterprise Vault Sales group to discuss these concerns.  For information on how to contact  Enterprise Vault Sales, please see https://www.enterprisevault.com/.

Please be sure to refer back to this document periodically as any changes to the status of the issue will be reflected here.

Issue/Introduction

Enterprise Vault Single Sign-On fails to work as expected with IBM Security Access Manager (IBM Security Verify)