- Login is met with 403 when authenticating through 3rd party IDP
- /var/log/cb/coreservices/debug.log shows the following exception:
2021-03-22 13:30:44 [61518] <err> cb.flask.blueprints.api_routes_saml - SSO assertion auth failure
Traceback (most recent call last):
File "/usr/share/cb/virtualenv/lib/python3.8/site-packages/cb/flask/blueprints/api_routes_saml.py", line 558, in saml_assertion
File "/usr/share/cb/virtualenv/lib/python3.8/site-packages/cb/flask/blueprints/api_routes_saml.py", line 193, in handle_assertion
File "/usr/share/cb/virtualenv/lib64/python3.8/site-packages/saml2/client_base.py", line 811, in parse_authn_request_response
resp = self._parse_response(
File "/usr/share/cb/virtualenv/lib64/python3.8/site-packages/saml2/entity.py", line 1507, in _parse_response
response.verify(keys)
File "/usr/share/cb/virtualenv/lib64/python3.8/site-packages/saml2/response.py", line 1045, in verify
if self.parse_assertion(keys):
File "/usr/share/cb/virtualenv/lib64/python3.8/site-packages/saml2/response.py", line 931, in parse_assertion
if not self._assertion(assertion, False):
File "/usr/share/cb/virtualenv/lib64/python3.8/site-packages/saml2/response.py", line 811, in _assertion
if not self.condition_ok():
File "/usr/share/cb/virtualenv/lib64/python3.8/site-packages/saml2/response.py", line 603, in condition_ok
raise Exception("AudienceRestrictions conditions not satisfied! (Local entity_id=%s)" % self.entity_id)
Exception: AudienceRestrictions conditions not satisfied! (Local entity_id=<instance name pulled from sso.conf>)
2021-04-14 19:40:29 [184255] <debug> saml2.response - AudienceRestriction - One condition not satisfied: https://<hostname/IP>:8443 != https://<hostname/ IP>