SAML error Login was unsuccessful! - Validation Failed : Invalid Signature on SAML Response×

  • 10 October 2017
  • 6 replies
  • 977 views


We've setup SSO with azure following the steps online, however when trying to login we receive 




Login was unsuccessful! - Validation Failed : Invalid Signature on SAML Response





Is anyone else experiencing this issue or able to shed some light on troubleshooting?



thanks 




This topic has been closed for comments

6 replies

Userlevel 4
Badge +12

Hello Lee,




We've converted this topic into a private ticket for effective troubleshooting. I hope you're already in touch with one of our super agents :)




Cheers!


Userlevel 4
Badge +12

**update from the support ticket**




SHA-1 certificate was still in use in Azure and there were no methods to generate a SHA-256 cert directly in Azure. In case if you're wondering on how to solve this, drop an email to us with the X.509 information so that we can help you with the SharedSecretKey.




Cheers!



I am following this description: 


https://docs.microsoft.com/en-us/azure/active-directory/active-directory-saas-freshdesk-tutorial




The error message after login:


Login was unsuccessful! - Validation Failed : Invalid Signature on SAML Response




The certificate hash is SHA256. What is the exact reason for the login failure? Not been able to configure SSO with Azure so far.




Userlevel 4
Badge +12

@Zsolt : Sorry that we're getting back to you with significant delay.Were you able to setup the SSO through Azure in your helpdesk? If you're still looking for assistance, please ping us here and we'll act on it right away.


Cheers!

"SAML error Login was unsuccessful!"

Followed the Azure AD SAML documentation in detail lots of time but still receive this error post redirect to domain.freshdesk.com/login/normal.


How can I get support to resolve this issue ?  Currently trialling various CRM products.


Thank you

Scott


Userlevel 4
Badge +12

Scott,


You can log in from 'Firefox' browser and there is a plugin called "SAML tracer" using which you could use to trace the response when a login is attempted using SAML SSO. You have to add that plugin to your Firefox browser and you can find the response under SAML tab in that plugin for each and every trace when a user tries to log into their SSO website.


If you're still not able to debug the issue with the tracer, kindly send the traced output to support(at)freshdesk(dot)com and one of our support heroes will help you fix this.


Cheers!