05-09-2019 07:44 AM - edited 02-21-2020 09:38 PM
Hi,
I have an issue with SAML authentication method.
If I tried to enter via VPN into my company I see this message:
May 09 15:51:53 [Lasso] func=xmlSecOpenSSLEvpSignatureVerify:file=/local/jenkins_engci_sjc/workspace/team_SSP/fxplatform/Builds/release__2.4.1_fcs_greenwich/build-smp-compile/fxos/linux/wrlinux/bitbake_build/tmp/work/corei7-64-wrs-linux/xmlsec1/1.2.20-r1/xmlsec1-1.2.20/src/openssl/signatures.c:line=493:obj=rsa-sha1:subj=EVP_VerifyFinal:error=18:data do not match:signature do not match
May 09 15:51:53 [SAML] consume_assertion: The profile cannot verify a signature on the message
[saml] webvpn_login_primary_username: SAML assertion validation failed.
Without SAML authentication the VPN goes up correctly.
#Confg
saml idp IDP_SSO_PRD
url sign-in https://xxx
base-url https://xxx
trustpoint idp saml-trust
trustpoint sp SAML-AUTH
signature rsa-sha256
force re-authentication
Thanks
Solved! Go to Solution.
05-21-2019 09:29 PM
05-09-2019 07:50 PM
05-10-2019 09:27 AM
The IDP certificate is trusted.
Also the ASA certificate must be trusted?
Thanks.
05-11-2019 09:23 PM
05-13-2019 07:59 AM
Hy,
my ASA version is 9.10(1)17
The IDP is SAP NetWeaver 7.3 Java.
IDP's log said "Login OK" but ASA side I see always:
May 13 16:46:04 [Lasso] func=xmlSecOpenSSLEvpSignatureVerify:file=/local/jenkins_engci_sjc/workspace/team_SSP/fxplatform/Builds/release__2.4.1_fcs_greenwich/build-smp-compile/fxos/linux/wrlinux/bitbake_build/tmp/work/corei7-64-wrs-linux/xmlsec1/1.2.20-r1/xmlsec1-1.2.20/src/openssl/signatures.c:line=493:obj=rsa-sha1:subj=EVP_VerifyFinal:error=18:data do not match:signature do not match
I looked at SAML's guide and seems easy to configure but I cannot understand what I miss.
05-13-2019 05:25 PM
05-14-2019 07:32 AM - edited 05-16-2019 08:19 AM
05-19-2019 01:52 PM
05-20-2019 05:20 AM
05-21-2019 09:29 PM
10-19-2021 11:38 AM
what is the solution ?
05-23-2019 06:36 AM
05-30-2019 03:10 AM
The idp IP is: 212.77.91.39
Unfortunatly I can't trace the traffic.
The buffer is always empty.
10-14-2020 09:38 AM
Can you please point me to the bug. I am getting the run around with TAC
09-25-2019 07:49 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide