Active Directory User cannot login to the WebUI using SSO SAML integration
search cancel

Active Directory User cannot login to the WebUI using SSO SAML integration

book

Article ID: 290881

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

  • Only certain users cannot login via SAML / SSO integration.
  • This error occurs in the CB SSO log file:
ParseError: not well-formed (invalid token): line 1, column 7146 
2019-05-07 10:45:00 [420005] <err> saml2.entity - Not well-formed XML 
2019-05-07 10:45:00 [420005] <err> saml2.client_base - XML parse error: not well-formed (invalid token): line 1, column 7146 
2019-05-07 10:45:00 [420005] <err> cb.flask.blueprints.api_routes_saml - SSO assertion auth failure 
Traceback (most recent call last):

Environment

  • EDR Server: All versions
  • SSO_SAML Integration

Cause

The group name of Active Directory account contained an special character (i.e.  Red_&_Sox ) 

Resolution

A workaround is to rename the AD group to not include the special characters.

Additional Information

  • The special character in this case was an ampersand, but this could be affected by other special characters