derekgreen Posted June 14, 2017 Posted June 14, 2017 Help! Numerous users are reporting the attached error when attempting to log in to the Service Portal. Any ideas?
Martyn Houghton Posted June 14, 2017 Posted June 14, 2017 @derekgreen Your single sign on trust certificate has expired. You need to login with the bypass option into the admin took and then reenter the URL to import the certificate from your SSO source system. I dig out the bypass option option URL and add it too this post shortly. Cheers Martyn
TrevorKillick Posted June 14, 2017 Posted June 14, 2017 A recent Post from Gerry details how to update your Single Sign On Configuration to contain the updated Certificate from your ADF Servers. Kind Regards Trevor Killick
Martyn Houghton Posted June 14, 2017 Posted June 14, 2017 @derekgreen You can log in with your non SSO admin user that would have been setup and provided as part of the Hornbill Switch On process using the url below, replacing your instance name. https://admin.hornbill.com/<instance_name>/?ESPBasic=true Then you can follow the steps as Trevor has linked to. Cheers Martyn
derekgreen Posted June 14, 2017 Author Posted June 14, 2017 Thanks guys. All of our ADFS configuration was done by a third party. How do I actually identify and update the certificate? I have attached a snip of the certificate(s) as presented in our SSO config.
Martyn Houghton Posted June 14, 2017 Posted June 14, 2017 @derekgreen Hopefully you have the endpoint URL of your ADFS server which you can use to import an updated certificate from. Our is along the lines of https://......../federationmetadata/2007-06/federationmetadata.xml but would be specific to your provider. Once you have this you can click on the button in the top right hand corner to to enter the endpoint an re-import an updated trust certificate in the dialog window that appears. As as workaround to get live app users in you could temporarily disable the SSO config and then choose to create passwords from the admin tool for your key users, whilst you sort out the SSO config. Cheers Martyn
Victor Posted June 14, 2017 Posted June 14, 2017 @derekgreen as @Martyn Houghton suggested you need either teh URL or the SAML metadata file (the XML file). You need to ask the ADSF guy to give you this. They know what it is. Until you get this you can temporarily disable certificate validation to allow your users to log in. EDIT: @Martyn Houghton disabling SSO allogether is indeed an option, but if you have hundreds of basic users.. well.. it might take a while to reset all passwords
Martyn Houghton Posted June 14, 2017 Posted June 14, 2017 @Victor Indeed disabling SSO is not the easy route, but is something we have in our Business Continuity plan if we lose our ADFS servers. Fingers crossed I never have to do it Cheers Martyn
derekgreen Posted June 14, 2017 Author Posted June 14, 2017 Not having much joy here I'm afraid. I have identified the url to the metadata xml but when I process it I get a message back saying empty xml.
derekgreen Posted June 14, 2017 Author Posted June 14, 2017 Hi Victor - I'd love to if only I could find it!
derekgreen Posted June 14, 2017 Author Posted June 14, 2017 Victor - would you be able to remotely access our ADFS server?
Victor Posted June 14, 2017 Posted June 14, 2017 @derekgreen I'm afraid can't... I simply don't know the product (ADFS) ... I can work with the XML file (or information) provided by the IdP (in this case ADFS) but to go in and look for it in the IdP itself I do not know
TrevorKillick Posted June 14, 2017 Posted June 14, 2017 @derekgreen The XML URL is typically something like this:https://adfs.yourdomain.com/FederationMetadata/2007-06/FederationMetadata.xml The exact subdomain should be in the entity Id against your SSO profile. Kind Regards Trevor Killick
nasimg Posted June 14, 2017 Posted June 14, 2017 If you have revert to the username/password option (not SSO), you don't need to reset the password individually. Tell your customers to use the forgot password option to reset it themselves. Regards Nasim 1
dconagh Posted September 4, 2017 Posted September 4, 2017 Hello, Was this ever resolved as I am experiencing the exact same problem. Thank you, Dan
Victor Posted October 18, 2017 Posted October 18, 2017 @dconagh oops... looks like we missed your reply, apologies Do you still experience the problem?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now