Description of problem: Following the documented [1] implementation of CloudForms SSO using IPA and RH SSO, attempting to log in fails, producing this error in the UI instead: Not Found The requested URL /saml2 was not found on this server. [1] Section 4.1.4.2.11, “Configuring External Authentication Using SAML” https://access.redhat.com/documentation/en-us/red_hat_cloudforms/4.5/html-single/general_configuration/#external_ipa_auth Removing the 'Master SAML Processing URL' value from the SSO client configuration resolved the problem. Version-Release number of selected component (if applicable): IPA : version: 4.5.0 CFME: 5.8.2.3 SSO: Server Version 7.1.3.GA How reproducible: Steps to Reproduce: 1. Implement as per documented procedure [1] 2. Attempt log in to CF appliance UI 3. Actual results: Error above appears. Expected results: Successful log in. Additional info: This may simply be a documentation error.
Hey Nik. Please confirm my understanding of the issue. The BZ seems to indicate that by removing the Master SAML Processing URL value from the SSO client configuration the issue is resolved. So my understanding is that the documentation may simply need to be updated to suggest removing the Master SAML Processing URL value from the SSO client configuration. Is that correct? Thank you! JoeV
Hi Joe - agreed, this does simply seem to be a documentation bug for downstream (CloudForms).
Assigning to Dayle for review. Dayle - see the above for what should be a simple fix to an issue a customer ran into when setting up authentication.
Hi Chris, I've removed the "Master SAML Processing URL" line from the table in the procedure under the heading "Configuring the HTTP Server for SAML", which looks like all that is needed for this particular bug. Would you mind reviewing please? Let me know if you think anything else is needed to be clear. https://github.com/ManageIQ/manageiq_docs/pull/606 [@Prasad, if you have other docs fixes needed for the attached case, please let us know of any related BZs.] Thank you, Dayle
Dayle, ack! will open new BZ with my findings soon.
Thank you Chris! I've also backported this to the gaprindshvili and fine branches in https://github.com/ManageIQ/manageiq_docs/pull/607 (merged) and PR #608. The 4.5 General Configuration guide now includes this change in "4.1.4.2.11. Configuring External Authentication Using SAML": https://access.redhat.com/documentation/en-us/red_hat_cloudforms/4.5/html-single/general_configuration/#servers