cancel
Showing results for 
Search instead for 
Did you mean: 

Unsolicited responses are not allowed for idp

Patrik_Renoud
Confirmed Champ
Confirmed Champ

Hi there,

We are using the Hyland identity server (v. 2.4.1) to login to our OnBase system (EP4, 20.8.10) with saml authentication and AzureAD.

When we log in directely with the Onbase AppNet server address, all is going well.

But when we try to use the myapps portal from Microsoft, we get an error:

Sustainsys.Saml2.Exceptions.Saml2ResponseFailedValidationException: Unsolicited responses are not allowed for idp

 

I suppose this behavior comes because of the idp-initiated-SSO must be allowed.

Is that right ?

Is this mode (idp-initiated-sso) can be supported by the hyland identity provider?

How can it be configured in the hyland idp server ?

 

Thanks in advance

1 ACCEPTED ANSWER

AdamShaneHyland
Employee
Employee

Hi @Patrik ,

 

The Hyland IDP does not support IdP-Initiated authentication.  Only SP-Initiated.  This is why you see the behavior that you do.

 

Best wishes.

View answer in original post

3 REPLIES 3

AdamShaneHyland
Employee
Employee

Hi @Patrik ,

 

The Hyland IDP does not support IdP-Initiated authentication.  Only SP-Initiated.  This is why you see the behavior that you do.

 

Best wishes.

Patrik_Renoud
Confirmed Champ
Confirmed Champ

Hello Adam,

 

Thank you for your answer - bad for us.

Is that capability in the backlog or does I post a new idea ?

Kind regard

Hi @Patrik ,

 

There is a feature epic for this functionality, however it is currently on the backlog as of OnBase Foundation EP5 and has not been scheduled for the next version.  I would recommend you create an Ideas post.  You can reference Jira Feature Epic IAMPRO-97 in your notes which is the development card to enhance the product.

 

Best wishes.

Getting started

Find what you came for

We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.