Troubleshooting Tip: SAML IdP authentication fails with '403 forbidden' error
| Description | This article describes how to resolve an issue where SAML IDP authentication fails with a '403 Forbidden' error and FortiAuthenticator is configured as an IDP. |
| Scope | FortiAuthenticator v6.6.1. |
| Solution | When a user enters the credentials and tries to authenticate, the authentication fails with the '403 Forbidden' error.
GUI debug logs from FortiAuthenticator show the following error:
2025-05-17T22:51:26.000917+05:30 FortiAuthenticator gui[1859] error fac.home.www-data.FastAPI.apps.saml.views.samlidp __init__ 140208609381248 SP Test assertion request error: 'NoneType' object has no attribute 'split' In the FortiAuthenticator, select Authentication -> SAML IdP -> Service Providers and check if the SP SLS (logout) URL is empty.
|


