<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Azure SAML authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-azure-saml-authentication/m-p/308932#M80114</link>
    <description>&lt;P&gt;Are you using Azure Cloud MFA or Azure MFA Server?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 31 Jan 2020 17:48:27 GMT</pubDate>
    <dc:creator>Maxstr</dc:creator>
    <dc:date>2020-01-31T17:48:27Z</dc:date>
    <item>
      <title>Global Protect Azure SAML authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-azure-saml-authentication/m-p/308893#M80107</link>
      <description>&lt;P&gt;PAN OS 8.1.6 currently&lt;/P&gt;&lt;P&gt;GP Client 4.1.13-2&amp;nbsp; and&amp;nbsp; 5.0.7-2 (testing)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attempting to use Azure SAML authentication&lt;/P&gt;&lt;P&gt;went through standard procedures..&lt;/P&gt;&lt;P&gt;import fed metadata xml from azure.&lt;/P&gt;&lt;P&gt;validate IDP cert unchecked.&lt;/P&gt;&lt;P&gt;Azure cert imports automatically and is valid.&lt;/P&gt;&lt;P&gt;auth profile with saml created (no message signing)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when Browsing to GP portal URL, redirection and Microsoft auth works fine and continues to Portal site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From logs..&lt;/P&gt;&lt;P&gt;&lt;U&gt;saml-signature-validated&lt;/U&gt;:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;SAML Assertion: signature is validated against IdP certificate (subject \'crt.azure_SAML_profile.shared\') for user&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;\'john.doe@here.com&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;U&gt;auth-success:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;'SAML SSO authenticated for user \'john.doe@here.com\'. auth profile \'azure-saml-auth\', vsys \'vsys4\', server&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; profile \'azure_SAML_profile\', IdP entityID \'&lt;A href="https://sts.windows.net/d77c7f4d-d767-461f-b625-8903327872/\" target="_blank"&gt;https://sts.windows.net/d77c7f4d-d767-461f-b625-8903327872/\&lt;/A&gt;', Fro&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next..&lt;/P&gt;&lt;P&gt;When I attempt to use the SAML auth profile with the GP gateway (different hostname/IP from Portal)&lt;/P&gt;&lt;P&gt;Fails..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The initial saml auth to the portal is successful in the logs...but then auth to the gateway fails with the below information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from Logs..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;saml-certificate error:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Failure while validating the signature of SAML message received from the IdP "&lt;A href="https://sts.windows.net/d77c7f4d-d&amp;nbsp;" target="_blank"&gt;https://sts.windows.net/d77c7f4d-d&amp;nbsp;&lt;/A&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;767-461f-b625-8903327872/", because the certificate in the SAML Message doesn\'t match the IDP certificate&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;configured on the IdP Server Profile "azure_SAML_profile". (SP: "Global Protect"), (Client IP: 70.131.60.24),&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(vsys:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;shared), (authd id: 6705119835185905969), (user: john.doe@here.com)' )&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;auth-fail:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SAML SSO authentication failed for user \'john.doe@here.com\'. Reason: SAML web single-sign-on failed. auth pr......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2020 14:26:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-azure-saml-authentication/m-p/308893#M80107</guid>
      <dc:creator>kevin.thomas</dc:creator>
      <dc:date>2020-01-31T14:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Azure SAML authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-azure-saml-authentication/m-p/308932#M80114</link>
      <description>&lt;P&gt;Are you using Azure Cloud MFA or Azure MFA Server?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2020 17:48:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-azure-saml-authentication/m-p/308932#M80114</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2020-01-31T17:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Azure SAML authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-azure-saml-authentication/m-p/309222#M80155</link>
      <description>&lt;P&gt;The log shows that it's failing while validating the signature of SAML.&lt;/P&gt;&lt;P&gt;You may try this out:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1) Uncheck 'Validate Identity Provider Certificate,' and 'Sign SAML Message to IDP' on the Device -&amp;gt; Server Profiles -&amp;gt; SAML Identity Provider.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;2) Set to 'None' in 'Certificate for Signing Requests' and 'Certificate Profile' on the Device -&amp;gt; Authentication Profile -&amp;gt; authentication profile you configured for Azure SAML.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 18:50:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-azure-saml-authentication/m-p/309222#M80155</guid>
      <dc:creator>AnalysisMan</dc:creator>
      <dc:date>2020-02-03T18:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Azure SAML authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-azure-saml-authentication/m-p/332117#M84000</link>
      <description>&lt;P&gt;Thank you much&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15381"&gt;@AnalysisMan&lt;/a&gt;&amp;nbsp;!!&amp;nbsp;&lt;/P&gt;&lt;P&gt;After hours of working on this, I finally came across your post and you have saved the day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It now works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2020 23:51:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-azure-saml-authentication/m-p/332117#M84000</guid>
      <dc:creator>cdg-sherman1</dc:creator>
      <dc:date>2020-06-06T23:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Azure SAML authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-azure-saml-authentication/m-p/554020#M112617</link>
      <description>&lt;P&gt;I have the same issue with Pingone through the gateway getting internal error 500, any inputs?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 17:05:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-azure-saml-authentication/m-p/554020#M112617</guid>
      <dc:creator>Vinod_Pathuri</dc:creator>
      <dc:date>2023-08-16T17:05:07Z</dc:date>
    </item>
  </channel>
</rss>

