CA Single Sign On Secure Proxy Server (SiteMinder)CA Single Sign On SOA Security Manager (SiteMinder)CA Single Sign-On
Issue/Introduction
Federation request is looping between the Authentication URL (redirect.jsp) and saml2sso URL.
The Web Agent error log shows the following error:
Agent failed to process request with return code: '-1'.
Environment
Release: 12.8.x Component: Access Gateway
Cause
The Access Gateway agent was configured to use an ACO (Agent Configuration Object) that was not based on the SPSDefaultSettings ACO template. This can cause odd behavior around authentications that take place on the Access Gateway Web Agent.
Resolution
The ACO used by the Access Gateway Agent should always be based on the SPSDefaultSettings ACO template.
Rebuilding the ACO based on this template to resolve the issue.