RSA Identity Governance and Lifecycle SAML SSO failing with error "Did not find user with attribute"
Originally Published: 2017-08-15
Article Number
Applies To
RSA Version/Condition: 7.0.0, 7.0.1, 7.0.2
Issue
08/15/2017 12:15:44.583 INFO (default task-97) [com.aveksa.server.authentication.AbstractSSOAuthenticatorImpl] SSOAuthenticator:getMasterEnterpriseUser(): Using column: userId
08/15/2017 12:15:44.587 ERROR (default task-97) [com.aveksa.server.authentication.AbstractSSOAuthenticatorImpl] Did not find user with attribute: USER_ID = jdoe
08/15/2017 12:15:44.849 INFO (default task-99) [com.aveksa.gui.pages.toolbar.login.SSOAuthenticatorHandler] SSOAuthenticator: isAuthenticator failed. Reason: Found 0 assertions when expected 1
08/15/2017 12:15:44.849 ERROR (default task-99) [com.aveksa.gui.pages.toolbar.login.SSOAuthenticatorHandler] com.aveksa.server.authentication.AuthenticationProviderException: Found 0 assertions when expected 1
Cause
Resolution
- Ensure that the attribute returned from the SAML authentication source is able to be mapped directly to an RSA Identity Governance and Lifecycle user attribute value that corresponds to the same user.
- Enter the correct value in the SAML configuration page for the UnifiedUserColumn. The column names can be chosen from any value user column in the table T_MASTER_ENTRERPRISE_USERS. Possible columns that may be used include but are not limited to USER_ID, EMAIL_ADDRESS, or any custom user attributed mapped to a a local user attribute such as CUS_ATTR_USER_CAS_15 that has as its value the same value as the attribute returned in the SAML assertion. Note that the user must be a valid user.
Notes
08/15/2017 12:15:44.849 ERROR (default task-99) [com.aveksa.gui.pages.toolbar.login.SSOAuthenticatorHandler] com.aveksa.server.authentication.AuthenticationProviderException: Found 0 assertions when expected 1
Related Articles
TERMINATION_DATE from Oracle HRMS Authentication System is not getting stored in RSA Identity Governance and Lifecycle 7.0 20Number of Views How to set up a CRL Distribution Point in a certificate during certificate manual approval 10Number of Views How to access RSA Registration Manager enrollment page without being warned that the site is not trusted (even through the… 8Number of Views AMPrime com.rsa.ucm.AuthManager.AmisCommandTargetException : Key not found 33Number of Views How to change the default Oracle Statistics History Retention period for RSA Identity Governance & Lifecycle 86Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?