SAML SSO Login is redirecting back to the login page

SAML SSO Login is redirecting back to the login page

Troubleshooting: SSO Login errors 

 

  1. Issue Title: SSO Login is redirecting back to the login page  

 

Description 

 

When using the “Login in with SSO” option in the Prolaborate login page, the user is redirected to the SSO site for Login credentials. After successful login in to the SSO site, Prolaborate is redirected back into the Login page instead of logging into Prolaborate. 

 

 

 

When the “Login with SSO” option is clicked, the user is redirected to the SSO site’s login page. 

 

 

 

After selecting the account that has to be logged on, the user is redirected back to the login page. 

 

 

Possible Reasons 

 

1. Incorrect Attribute Mapping 

  • The issue might occur due to the misconfiguration of the “Attribute Mapping” sections in the SAML Single Sign On page of the Prolaborate. 

  • If there are any errors in the attribute mapping, the users are not logged into the Prolaborate instead they are redirected back to the Login page. 

  • This issue can be solved by entering the appropriate attributes in the Attribute mapping section in both Prolaborate and the Identity Provider page. 

  

 

 

 

2. Invalid or Expired .PFX Certificate 

 

  • Viktor from Huddinge Municipality reported that they are experiencing the above error when logging in with SSO 

  • On checking with the customer was using Nexes Hybrid Access Gateway. 

  • The customer didn’t enable the SAML 2.0 response, and the attribute mapping was also not configured. 

SAML 2.0 Response 

  

Attribute Mapping 

 

  • We asked the customer to configure them and try again, but the issue was still not resolved. 

  • We asked the customer for the Debug logs to investigate this issue further. 

  • On analyzing the logs, we found that the .PFX certificate is expired.  

2023-05-09T10:55:37.3695062+02:00 [DBG] (ComponentSpace.Saml2.Certificates.CertificateValidator) The X.509 certificate with subject name CN=Huddinge kommun SAML Signing Key v1, OU=IT, O=Huddinge kommun, L=Huddinge, S=Sweden, C=SE, serial number 00B1D60A998004C5F9 and thumbprint 1482396CC0697C19E63C1CF66724581B4469C841 is being validated. 

2023-05-09T10:55:37.3695425+02:00 [DBG] (ComponentSpace.Saml2.Certificates.CertificateValidator) The certificate expired on 2019-11-29 16:05:00. 

The highlighted log shows that the certificate has been expired. 

  • We then asked the customer to use a valid certificate and let us know. 

  • The customer replied that the issue was resolved after using a valid certificate. 

 

3. IDP User changed to Registered User 

- We performed a planned upgrade activity for Tenncare, the user George Bikki’s account was changed to a Registered User. 

- The user was not returned back as an SSO user, which is the cause of this issue. 

 

 

4. Bug in Prolaborate Version 4.4.1 

  • In Prolaborate version 4.4.1, there is a known bug where the login with SSO button redirects to the login page if a registered user and an IDP user share the same email ID. 

 


5. License could be fully occupied at User and license management.

The login issue may also arise if all available licenses are fully occupied in the User and License Management section.


Initial Response 

 

Hi <Customer>, 

Thank you for reaching out to Prolaborate Support. 

We understand that you are unable to login with SSO in your Prolaborate. We are investigating this issue with our team and will get back to you with an update at the earliest. In the meantime, could you please let us know the below information to help us with the investigating, 

1. Please share us a screenshot of the Prolaborate “Single SIgn-On page. 

2. Screenshot of IDP configuration page. 

3. IDP metadata and .cert file. 

4. Short video reproducing the issue when clicking the “Login with SSO” button. 

5. Also ensure that the ‘.PFX’ certificate (Domain) which was uploaded to the Service Provider is valid. 

Please check and let us know if you any questions or concerns. 

 

Response 

 

Hi George, 

Sorry for the inconvenience caused earlier! 

Upon further investigation based on the logs, we have identified the problem. The issue was that Tenncare's IAM IDP ID was not rendering properly. We have made the necessary changes to address this issue. 

 

We have double-checked and verified that the problem is fixed and won't come up again. 

Could you please check once again to see if everything is working fine now? 

 

For Reason 3 Response: 

Hi [Customer Name], 

Thank you for your patience. 

After conducting further investigation, we have observed from the log file that the user with the email address [INCLUDE EMAIL ID OF THE USER] is already registered in Prolaborate User Management. Due to a bug in Prolaborate version 4.4.1, the system does not allow the addition of duplicate email IDs in Prolaborate User Management. This bug has been addressed and fixed in the latest version of Prolaborate 

To resolve the issue at hand, please follow the steps outlined below: 

1. Rename the existing email address associated with [Email ID of the user] and save the changes. 

2. Instead of removing the user, we recommend renaming the email address to minimize any impact on the sections and group configurations. 

3. Attempt to log in with SSO again from Prolaborate to check if you can successfully log in. 

4. Once logged in, please reassign the IDP user to the appropriate user groups, referring to the registered user (mentioned in the first point). 

If following the above steps resolves the issue, we strongly recommend considering an upgrade to the latest version of Prolaborate. 

Please try the suggested steps and let us know the outcome. 

Thank you. 

 

Tags 

invalid certificate, expired certificate, saml issue, nexes SSO, sso redirct login page, Okta sso, Invalid attributes, Attributes mapping 

 

 

 


    • Related Articles

    • Known Issues – SAML SSO

      Q1: SSL (.pfx) certificate password validation in SAML Sign On page Description 1. We encountered a problem with the Prolaborate SAML settings page when investigating an issue for Zabka. 2. The SSL (.pfx) password is not being validated in the SAML ...
    • Troubleshooting - SAML SSO

      Q: "404" error thrown when the user use SSO login Description The customer reported 404 error while trying to login using SSO Possible Reasons: 1. Certificate could have expired. First response – Troubleshooting Steps (This is the initial Mail to the ...
    • FAQ's - SAML SSO

      Q1: After the Prolaborate upgrade, Single Sign-On (SSO) was unable to launch, and an "Access denied" error is displayed. Answer This issue may have arisen due to a glitch in the system. To remedy this, please follow these steps: Reconfigure the SAML ...
    • Prolaborate Access Control & SSO

      This document consolidates information from customer reported issues and FAQs related to Prolaborate’s Access Control Profiles, SAML Single SignOn (SSO) configuration, readonly access, and a known login issue after license changes. It is intended to ...
    • Known issue: Access denied error when clicking SSO in Prolaborate(Autoscaling environment)

      "Access denied" error when clicking SSO in Prolaborate. Description: The customer reported being unable to access Prolaborate. When clicking the SSO, they encountered an "access denied" error in Prolaborate. Possible Reason: As confirmed by the Dev ...