Bug 1519310 - CloudForms SAML/SSO fails - The requested URL /saml2 was not found on this server
Summary: CloudForms SAML/SSO fails - The requested URL /saml2 was not found on this se...
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Documentation (Show other bugs)
(Show other bugs)
Version: 5.8.0
Hardware: Unspecified Unspecified
medium
medium
Target Milestone: GA
: 5.9.0
Assignee: Dayle Parker
QA Contact: Chris Budzilowicz
URL:
Whiteboard:
Keywords:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-11-30 15:12 UTC by ncatling
Modified: 2017-12-08 02:20 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Doc should be updated
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-12-08 02:20:35 UTC
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description ncatling 2017-11-30 15:12:33 UTC
Description of problem:

Following the documented [1] implementation of CloudForms SSO using IPA and RH SSO, attempting to log in fails, producing this error in the UI instead:

Not Found
The requested URL /saml2 was not found on this server.

[1] Section 4.1.4.2.11, “Configuring External Authentication Using SAML”
https://access.redhat.com/documentation/en-us/red_hat_cloudforms/4.5/html-single/general_configuration/#external_ipa_auth

Removing the 'Master SAML Processing URL' value from the SSO client configuration resolved the problem.


Version-Release number of selected component (if applicable):
IPA : version: 4.5.0
CFME: 5.8.2.3
SSO: Server Version  7.1.3.GA

How reproducible:


Steps to Reproduce:
1. Implement as per documented procedure [1]
2. Attempt log in to CF appliance UI
3.

Actual results:

Error above appears.

Expected results:

Successful log in.


Additional info:

This may simply be a documentation error.

Comment 2 Joe Vlcek 2017-11-30 15:26:57 UTC
Hey Nik.

Please confirm my understanding of the issue. The BZ seems to indicate that by removing the Master SAML Processing URL value from the SSO client configuration the issue is resolved. So my understanding is that the documentation may simply need to be updated to suggest removing the Master SAML Processing URL value from the SSO client configuration. Is that correct?

Thank you! JoeV

Comment 4 ncatling 2017-12-01 10:45:40 UTC
Hi Joe - agreed, this does simply seem to be a documentation bug for downstream (CloudForms).

Comment 5 Andrew Dahms 2017-12-04 00:15:02 UTC
Assigning to Dayle for review.

Dayle - see the above for what should be a simple fix to an issue a customer ran into when setting up authentication.

Comment 6 Dayle Parker 2017-12-06 02:30:20 UTC
Hi Chris,

I've removed the  "Master SAML Processing URL" line from the table in the procedure under the heading "Configuring the HTTP Server for SAML", which looks like all that is needed for this particular bug.

Would you mind reviewing please? Let me know if you think anything else is needed to be clear.

https://github.com/ManageIQ/manageiq_docs/pull/606

[@Prasad, if you have other docs fixes needed for the attached case, please let us know of any related BZs.]

Thank you,
Dayle

Comment 9 Prasad Mukhedkar 2017-12-06 07:30:39 UTC
Dayle, ack! will open new BZ with my findings soon.

Comment 11 Dayle Parker 2017-12-08 02:20:35 UTC
Thank you Chris! I've also backported this to the gaprindshvili and fine branches in https://github.com/ManageIQ/manageiq_docs/pull/607 (merged) and PR #608.

The 4.5 General Configuration guide now includes this change in "4.1.4.2.11. Configuring External Authentication Using SAML":

https://access.redhat.com/documentation/en-us/red_hat_cloudforms/4.5/html-single/general_configuration/#servers


Note You need to log in before you can comment on or make changes to this bug.