EducationSoftwareStrategy.com
StrategyCommunity

Knowledge Base

Product

Community

Knowledge Base

TopicsBrowse ArticlesDeveloper Zone

Product

Download SoftwareProduct DocumentationSecurity Hub

Education

Tutorial VideosSolution GalleryEducation courses

Community

GuidelinesGrandmastersEvents
x_social-icon_white.svglinkedin_social-icon_white.svg
Strategy logoCommunity

© Strategy Inc. All Rights Reserved.

LegalTerms of UsePrivacy Policy
  1. Home
  2. Topics

KB485377: “Error in login” appears using SAML authentication with assertion encryption enabled with MicroStrategy Web after upgrading to m2021 Update 4


Pascal Deguine

Principal Product Specialist • Strategy


This article describes a SAML configuration issue that may occur after upgrading to m2021 Update 4, when SAML assertion encryption is enabled while SAML message signing is disabled.

Description


After upgrading Strategy Web to m2021 Update 4, SAML authentication fails with the following error page:

ka04W000001IuO9QAK_0EM4W000004YEy0.jpeg

“Error in login – Please contact your administrator."
 

Cause


One possible root cause is that the SAML assertion is encrypted but the SAML message is not signed by the Identity Provider. The SAML libraries used for Strategy 2021 Update 4 and above require the SAML message to be signed when SAML assertions are encrypted.
To verify if this scenario applies, analyse the SAML response that is issued by your Identity Provider. One approach to capture SAML responses is to use a browser plugin such as Chrome SAML Panel as seen on the screenshot below:

ka04W000001IuO9QAK_0EM4W000004YEzm.jpeg
  • The SAML assertion is encrypted when the CipherData section of the SAML response contains an encrypted CyperValue.
ka04W000001IuO9QAK_0EM4W000004YEzw.jpeg

 

  • The SAML message is not signed when there is no Signature section included in the SAML response:
ka04W000001IuO9QAK_0EM4W000004YF0L.jpeg

 

Action


1.    Contact your Identity Provider Administrator to enable SAML message signing.
2.    Disable SAML assertion encryption on the Strategy Web SAML configuration page and contact your Identity Provider administrator to apply the change on the Identity Provider side.
 
 
 


Comment

0 comments

Details

Knowledge Article

Published:

February 23, 2022

Last Updated:

February 23, 2022