<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hi,  I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/discussions/f/administration/6365/hi-i-am-trying-to-setup-saml-authentication-via-admin-console-in-app</link><description>Hi, I am trying to setup SAML Authentication via Admin Console in Appian 7.11. When I am trying to upload the Service Provider Certificate (.pem), it is throwing me error like &amp;quot;Failed to import certificate&amp;quot;. I have converted both signed and self-signed</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/25680?ContentTypeID=1</link><pubDate>Fri, 18 Dec 2015 10:23:45 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:612eaad2-9c81-4449-8814-4924581ad68a</guid><dc:creator>nileshr</dc:creator><description>It is expected only when we already have active session. I tried on different systems and cleared the browser cache as well but it is redirecting everytime on the IDP side. For the first time it should always open APPIAN login page which is not happening now.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/25679?ContentTypeID=1</link><pubDate>Fri, 18 Dec 2015 07:02:45 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:05589c88-2657-43a7-b342-17fd8528f871</guid><dc:creator>Tom Ryan</dc:creator><description>If I understand the behavior correctly, this is expected unless you already have an active session with your IDP/SSO.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/25656?ContentTypeID=1</link><pubDate>Thu, 17 Dec 2015 17:32:08 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:20eae8cc-2c76-49e2-8b70-03faa8ee5acb</guid><dc:creator>nileshr</dc:creator><description>Hi Tom,&lt;br /&gt;When I tried to implement IDP initiated SSO, it is working fine. But the problem is that whenever I hit the url like &amp;quot;&lt;a href="https://example.com/suite"&gt;https://example.com/suite&amp;quot;&lt;/a&gt; in browser, it is redirecting me to IDP side everytime and login into APPIAN by validating the Username, instead it should open APPIAN login page, where I provided the link for &amp;quot;Login with SSO&amp;quot;. To bypass SAML configuration we need to type &amp;quot;&lt;a href="https://example.com/suite/portal/loginPage.none"&gt;example.com/.../loginPage.none&amp;quot;&lt;/a&gt;&lt;br /&gt;It was working fine till 7.10 in which after implementing SSO whenever we tried to access the url it is redirecting to APPIAN login page.&lt;br /&gt;Is this a bug or the functionality in Appian 7.11 saml authentication?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/25543?ContentTypeID=1</link><pubDate>Tue, 15 Dec 2015 04:38:25 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:c3b64105-448f-404c-ad03-3670408ffe1e</guid><dc:creator>Tom Ryan</dc:creator><description>It seems that either the response is missing or incomplete. Can you do a trace of the SAML request using either Fiddler or the SAML Tracer Addon for Firefox&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/25519?ContentTypeID=1</link><pubDate>Mon, 14 Dec 2015 12:53:15 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:8553f055-a080-4fc7-a0e1-8973defb4373</guid><dc:creator>nileshr</dc:creator><description>I have used the IDP metadata which contain only one &amp;lt;EntityDescriptor&amp;gt; tag. And it is giving me the same above error. Any suggestions on this.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/25506?ContentTypeID=1</link><pubDate>Mon, 14 Dec 2015 04:34:04 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:68cb867f-bfea-4a33-9bb0-57577a4fb0d3</guid><dc:creator>Tom Ryan</dc:creator><description>Does your IDP metadata file contain multiple &amp;lt;EntityDescriptor&amp;gt; tags? This has been seen to cause similar issues in the past. If so, can you test with only using one?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/25464?ContentTypeID=1</link><pubDate>Fri, 11 Dec 2015 10:32:57 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:43592f20-05ad-4fed-87b0-23bbed13dbdc</guid><dc:creator>nileshr</dc:creator><description>@Tom: I have tried to reproduce the issue again and made some changes but still facing the same issue. Below is the error from app-server.log:&lt;br /&gt;&lt;br /&gt;DEBUG org.springframework.security.web.access.intercept.FilterSecurityInterceptor - Authorization successful&lt;br /&gt;2015-12-09 13:24:30,913 [ajp-/0.0.0.0:8009-4] DEBUG org.springframework.security.web.access.intercept.FilterSecurityInterceptor - RunAsManager did not change Authentication object&lt;br /&gt;2015-12-09 13:24:30,913 [ajp-/0.0.0.0:8009-4] DEBUG org.springframework.security.web.FilterChainProxy - /saml/AssertionConsumer at position 13 of 13 in additional filter chain; firing Filter: 'UserActivityFilter'&lt;br /&gt;2015-12-09 13:24:30,914 [ajp-/0.0.0.0:8009-4] DEBUG org.springframework.security.web.FilterChainProxy - /saml/AssertionConsumer reached end of additional filter chain; proceeding with original chain&lt;br /&gt;2015-12-09 13:24:30,914 [ajp-/0.0.0.0:8009-4] DEBUG org.springframework.security.web.util.matcher.AntPathRequestMatcher - Checking match of request : '/saml/assertionconsumer'; against '/api/**'&lt;br /&gt;2015-12-09 13:24:30,915 [ajp-/0.0.0.0:8009-4] DEBUG org.springframework.security.web.util.matcher.AntPathRequestMatcher - Checking match of request : '/saml/assertionconsumer'; against '/saml/**'&lt;br /&gt;2015-12-09 13:24:31,099 [ajp-/0.0.0.0:8009-4] ERROR com.appiancorp.security.auth.saml.SamlTestServlet - Unexpected exception during SAML authentication test&lt;br /&gt;java.lang.IndexOutOfBoundsException: Index: 0&lt;br /&gt; at java.util.Collections$EmptyList.get(Collections.java:4454)&lt;br /&gt; at org.opensaml.xml.util.LazyList.get(LazyList.java:90)&lt;br /&gt; at org.opensaml.xml.util.ListView.get(IndexedXMLObjectChildrenList.java:312)&lt;br /&gt; at org.opensaml.xml.util.ListView.get(IndexedXMLObjectChildrenList.java:238)&lt;br /&gt; at com.appiancorp.security.auth.saml.IdentityProviderManager.getName(IdentityProviderManager.java:133)&lt;br /&gt; at com.appiancorp.security.auth.saml.IdentityProviderManager.createSamlAuthenticationToken(IdentityProviderManager.java:118)&lt;br /&gt; at com.appiancorp.security.auth.saml.SamlTestServlet.handlePost(SamlTestServlet.java:102)&lt;br /&gt; at com.appiancorp.security.auth.saml.SamlTestServlet.handleRequest(SamlTestServlet.java:76)&lt;br /&gt; at com.appiancorp.security.auth.saml.SamlTestServlet.service(SamlTestServlet.java:61)&lt;br /&gt; at javax.servlet.http.HttpServlet.service(HttpServlet.java:847)&lt;br /&gt; at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:295)&lt;br /&gt; at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:214)&lt;br /&gt; at com.appiancorp.ap2.EntryFilter.doFilter(EntryFilter.java:40)&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/25129?ContentTypeID=1</link><pubDate>Tue, 01 Dec 2015 02:50:22 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2829bd43-417f-4881-b860-15f2c6ec7dac</guid><dc:creator>Tom Ryan</dc:creator><description>Can you do the following:&lt;br /&gt;1. Set the increased logging levels as I described in my previous note (if you didn&amp;#39;t already)&lt;br /&gt;2. Reproduce the issue then attach the latest app server log&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/25099?ContentTypeID=1</link><pubDate>Mon, 30 Nov 2015 12:36:52 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:281b7462-d10a-434b-8b83-53bfbb909020</guid><dc:creator>nileshr</dc:creator><description>Hi Tom,&lt;br /&gt;I am able to import the signed certificate in Admin console now. It was working fine on Appian 7.10. So I just migrated the SSO configuration to 7.11. AD server is the IDP.&lt;br /&gt;But still I am getting the below error in application-server.log:&lt;br /&gt;ERROR: com.appiancorp.security.auth.saml.SamlTestServlet - Unexpected exception during SAML authentication test&lt;br /&gt;java.lang.IndexOutOfBoundsException : Index: 0&lt;br /&gt;Please find the screenshot of SAML configuration in Admin console.&lt;br /&gt;Could you please help me in resolving this?&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="/cfs-filesystemfile/__key/communityserver-discussions-components-files/12/SAML.JPG"&gt;&lt;img src="/cfs-filesystemfile/__key/communityserver-discussions-components-files/12/SAML.JPG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/25050?ContentTypeID=1</link><pubDate>Fri, 27 Nov 2015 02:33:04 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:8dc75200-3167-440a-8605-af968cf14f3d</guid><dc:creator>Tom Ryan</dc:creator><description>You will need to look at the app server logs to see more details as to what is going wrong. If the logs don&amp;#39;t show anything helpful, locate the following properties in &amp;lt;Appian Home&amp;gt;/ear/suite.ear/resources/appian_log4j.properties and set them as follows:&lt;br /&gt;&lt;br /&gt;log4j.logger.com.appiancorp.security=DEBUG&lt;br /&gt;log4j.logger.org.springframework.security=DEBUG&lt;br /&gt;&lt;br /&gt;Then you should see some more detailed logs. If you still do not see anything helpful, check with your IDP to see whether they have anything logged on their side.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/25046?ContentTypeID=1</link><pubDate>Thu, 26 Nov 2015 17:18:44 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:cde7cd14-7d55-4905-a087-fee1639e4f55</guid><dc:creator>nileshr</dc:creator><description>Thanks Tom for your help. Now I am able to upload the self-signed certificate but still facing the issue while uploading signed CA certificate.I tried to test it using self-signed certificate and after uploading the Identity Provider Metadata file, when tried to login it is giving me error like &amp;quot;Authentication was unsuccessful.&lt;br /&gt;Reason: Unexpected error occurred during SAML authentication test.&amp;quot; Please find the screenshot for the error:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="/cfs-filesystemfile/__key/communityserver-discussions-components-files/12/3731.Capture1.JPG"&gt;&lt;img src="/cfs-filesystemfile/__key/communityserver-discussions-components-files/12/3731.Capture1.JPG" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/24968?ContentTypeID=1</link><pubDate>Tue, 24 Nov 2015 02:51:15 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:e387c809-fdc3-423f-9f16-3b460ef26554</guid><dc:creator>Tom Ryan</dc:creator><description>If you are referring to the sample one you attached, that is not a valid certificate. &lt;br /&gt;&lt;br /&gt;You can try generating a new certificate/key pair by following steps like the ones here: &lt;a href="http://stackoverflow.com/questions/10175812/how-to-create-a-self-signed-certificate-with-openssl"&gt;stackoverflow.com/.../how-to-create-a-self-signed-certificate-with-openssl&lt;/a&gt;. You will need to combine the key and the cert into the same file.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/24936?ContentTypeID=1</link><pubDate>Mon, 23 Nov 2015 12:36:50 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:31f2f6b3-148e-4fb0-bb1e-7e6c112f6672</guid><dc:creator>nileshr</dc:creator><description>No, I don&amp;#39;t see any issues related to this in app server log. Can you please try from your end, if you can able to import the certificate.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/24924?ContentTypeID=1</link><pubDate>Mon, 23 Nov 2015 02:51:58 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:12de4538-f127-4752-9bfe-334482e13c62</guid><dc:creator>Tom Ryan</dc:creator><description>Are you seeing any more detailed errors in the app server log?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/24884?ContentTypeID=1</link><pubDate>Fri, 20 Nov 2015 10:39:58 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:9bc9ad11-b32b-4c1f-9e2f-83a853ac19ee</guid><dc:creator>nileshr</dc:creator><description>@Tom I had provided the password in Service Provider Certificate Password field. But it is giving the error as soon as I upload the certificate.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Hi,&lt;br /&gt;&lt;br /&gt;I am trying to setup SAML Authentication via Admin Console in App</title><link>https://community.appian.com/thread/24879?ContentTypeID=1</link><pubDate>Fri, 20 Nov 2015 07:57:56 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f6c4fc01-116e-4720-be89-c07a38b33e5e</guid><dc:creator>Tom Ryan</dc:creator><description>Does the certificate require a password? If this is the case it will not import successfully until the password is supplied. Are you seeing any errors in the app server log?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>