403 error after updating SPID value in federation config
search cancel

403 error after updating SPID value in federation config

book

Article ID: 401183

calendar_today

Updated On:

Products

SITEMINDER CA Single Sign On Federation (SiteMinder) CA Single Sign On Agents (SiteMinder) CA Single Sign On Secure Proxy Server (SiteMinder)

Issue/Introduction

After updating a working SAML configuration with a new SPID value, users began receiving a 403 error when trying to reach the application.  The error seems to be happening immediately upon making the request; user is never redirected for authentication. 

Environment

All Supported Environments

Cause

Upon checking the FWSTrace.log, an error message indicated the SPID could not be found.  The SPID value, which was in URL format, appeared URL-encoded in the log.  The SPID value was not URL-encoded in the config.  This was causing the mismatch.

Resolution

Submit the IDP-initiated request without URL-encoding the SPID value.  The SPID value must always be an exact match for what is specified in the config.