cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
901
Views
0
Helpful
8
Replies

Unable to enable SSO on Unity connection

smccloud1
Level 1
Level 1

I am trying to enable SAML SSO on one of our lab servers and no matter what I do I cannot get the "Enable SAML SSO" button to work.  I am logged in as an administrator, and I have tried multiple administrator accounts, but none of them work.

 

Version 12.5.1.14900-45

8 Replies 8

By the look of your screenshot it looks like you have not completed the export of the meta data. This is the very first thing you need to do to enable SSO. The rest of the steps are outlined in  documentation. Advise you to review it.



Response Signature


I have exported the metadata multiple times.  Nothing changes.

That’s not really what your screenshot shows. It states meta data never exported.

6B4E0C5B-551B-400C-90CD-74FDD01CF8CE.jpeg

But however, let’s go ahead with this. Have you got this meta data setup as a trust in your IdP and then imported the meta date from the IdP on your system?



Response Signature


Yes, I have.  The reason it looks like I haven't exported it is I have been working on this process for over a week now and have had to restart my browser a few times.  I am thinking that something is not working with my LDAP setup because I can no longer find my SSO Admin user (that I used for my other lab system) in LDAP on this box.  Is my thought correct that if I cannot find a LDAP administrator I will not be able to enable SSO?

Not AFAIK off. It sounds like you’re entire system is misbehaving quite oddly. I would think that you need TAC involved in this.



Response Signature


The problem with this is it's a lab system, they tend to not like to help us (lab is in one of the systems we develop against).  It would probably be faster for me to rebuild it than to get TAC to help me figure out the issue.

We also have lab instances and we never had any issue with getting support from TAC.



Response Signature


Even if you restart your browser or the system it should still show that you have done the export. Out of curiosity, have you tried with any of the other options for what certificate to use for the meta data export? We have always used the Tomcat cert and one per cluster instead of the options that you have selected in your screenshot.



Response Signature