SAML Authentication Issue for Administrator Interface allows Administrator Users login with any password in Portal Managment Console
search cancel

SAML Authentication Issue for Administrator Interface allows Administrator Users login with any password in Portal Managment Console

book

Article ID: 375697

calendar_today

Updated On:

Products

CA Identity Suite

Issue/Introduction

Within the Identity Portal, the User Interface is functioning correctly with SAML authentication. However, the Administrator Interface allows login with the Administrator username and any password, without returning an incorrect password error.

Environment

Identity Suite Vaap 14.4.2 CHF1
Identity Portal 14.4.2 CHF1 Standalone

Cause

The issue was caused by a misconfiguration in the WebServices Properties of Management Console of Identity Management. Specifically, the "Admin Password is required" option was not properly enforced. This setting should remain selected to ensure that the system requires the correct password for administrator logins, especially in environments using SAML authentication.

Resolution

Ensure that the Home -> Environments -> <Environment Name> -> Advanced Settings -> Web Services -> "Admin password is required" option is selected in Web Services properties

Additional Information

The "Admin Password is required" option is selected by default.  Only in case integration with traditional SiteMinder authentication, then the option will be deselected. If is using SAML authentication, that SHOULD NOT be deselected