Security

 View Only
last person joined: 21 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

IDP initiated SSO / SAML with Azure AD "RelayState invalid / missing"

This thread has been viewed 37 times
  • 1.  IDP initiated SSO / SAML with Azure AD "RelayState invalid / missing"

    Posted Nov 01, 2020 12:48 PM
    Hi, 

    We're using Azure AD and I've configured our Clearpass Server to use SAML as SP. The SP initiated SSO from the clearpass login page is working well, but if i try to login from MyApps Dashboar at AAD I'm getting an 403. 
    We using the Azure application proxy for the way back into our internal network.  

    Any ideas what I've probalby done wrong or how to analyze the issue further? 

    Thanks
    Jonny




    ------------------------------
    Jonny
    ------------------------------


  • 2.  RE: IDP initiated SSO / SAML with Azure AD "RelayState invalid / missing"

    Posted Nov 01, 2020 01:13 PM
    Have you replaced the default cert on the application in Azure?

    ------------------------------
    Victor Fabian
    ------------------------------



  • 3.  RE: IDP initiated SSO / SAML with Azure AD "RelayState invalid / missing"

    Posted Nov 01, 2020 01:19 PM
    Yep, CNAME was created and I've uploaded the correct certificate. From my understanding, all settings and forwarders at AAD are correct. I've have been authenticated successfully but clearpass miss something. There are no log entries at the access tracker.

    ------------------------------
    Jonny 
    ------------------------------



  • 4.  RE: IDP initiated SSO / SAML with Azure AD "RelayState invalid / missing"
    Best Answer

    Posted Nov 02, 2020 12:40 PM
    CPPM does not support IdP-initiated logins. You'd need to just add a static link in MyApps.

    ------------------------------
    Tim C
    ------------------------------



  • 5.  RE: IDP initiated SSO / SAML with Azure AD "RelayState invalid / missing"

    Posted Nov 03, 2020 01:52 AM
    @timms 
    Thanks for clarification! Didn't thought about this possibility.
    Will try it with a static link and application proxy.​

    ------------------------------
    Jonny
    ------------------------------



  • 6.  RE: IDP initiated SSO / SAML with Azure AD "RelayState invalid / missing"

    EMPLOYEE
    Posted Oct 25, 2021 12:55 PM
    I had a different fix. For me, the cert that was popped out of the Base64 section was different than the Raw option. Raw worked, but Base64 did not. As well, the Test never worked for me...only logging in directly to ClearPass.

    ------------------------------
    Greg Kamer
    ------------------------------