Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1519310 - CloudForms SAML/SSO fails - The requested URL /saml2 was not found on this server
CloudForms SAML/SSO fails - The requested URL /saml2 was not found on this se...
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Documentation (Show other bugs)
Unspecified Unspecified
medium Severity medium
: GA
: 5.9.0
Assigned To: Dayle Parker
Chris Budzilowicz
Depends On:
  Show dependency treegraph
Reported: 2017-11-30 10:12 EST by ncatling
Modified: 2017-12-07 21:20 EST (History)
11 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Doc should be updated
Story Points: ---
Clone Of:
Last Closed: 2017-12-07 21:20:35 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description ncatling 2017-11-30 10:12:33 EST
Description of problem:

Following the documented [1] implementation of CloudForms SSO using IPA and RH SSO, attempting to log in fails, producing this error in the UI instead:

Not Found
The requested URL /saml2 was not found on this server.

[1] Section, “Configuring External Authentication Using SAML”

Removing the 'Master SAML Processing URL' value from the SSO client configuration resolved the problem.

Version-Release number of selected component (if applicable):
IPA : version: 4.5.0
SSO: Server Version  7.1.3.GA

How reproducible:

Steps to Reproduce:
1. Implement as per documented procedure [1]
2. Attempt log in to CF appliance UI

Actual results:

Error above appears.

Expected results:

Successful log in.

Additional info:

This may simply be a documentation error.
Comment 2 Joe Vlcek 2017-11-30 10:26:57 EST
Hey Nik.

Please confirm my understanding of the issue. The BZ seems to indicate that by removing the Master SAML Processing URL value from the SSO client configuration the issue is resolved. So my understanding is that the documentation may simply need to be updated to suggest removing the Master SAML Processing URL value from the SSO client configuration. Is that correct?

Thank you! JoeV
Comment 4 ncatling 2017-12-01 05:45:40 EST
Hi Joe - agreed, this does simply seem to be a documentation bug for downstream (CloudForms).
Comment 5 Andrew Dahms 2017-12-03 19:15:02 EST
Assigning to Dayle for review.

Dayle - see the above for what should be a simple fix to an issue a customer ran into when setting up authentication.
Comment 6 Dayle Parker 2017-12-05 21:30:20 EST
Hi Chris,

I've removed the  "Master SAML Processing URL" line from the table in the procedure under the heading "Configuring the HTTP Server for SAML", which looks like all that is needed for this particular bug.

Would you mind reviewing please? Let me know if you think anything else is needed to be clear.


[@Prasad, if you have other docs fixes needed for the attached case, please let us know of any related BZs.]

Thank you,
Comment 9 Prasad Mukhedkar 2017-12-06 02:30:39 EST
Dayle, ack! will open new BZ with my findings soon.
Comment 11 Dayle Parker 2017-12-07 21:20:35 EST
Thank you Chris! I've also backported this to the gaprindshvili and fine branches in https://github.com/ManageIQ/manageiq_docs/pull/607 (merged) and PR #608.

The 4.5 General Configuration guide now includes this change in " Configuring External Authentication Using SAML":


Note You need to log in before you can comment on or make changes to this bug.