Description | This article describes how to resolve an issue where SAML IDP authentication fails with a '403 Forbidden' error and FortiAuthenticator is configured as an IDP. |
Scope | FortiAuthenticator v6.6.1. |
Solution | When a user enters the credentials and tries to authenticate, the authentication fails with the '403 Forbidden' error.
GUI debug logs from FortiAuthenticator show the following error:
2025-05-17T22:51:26.000917+05:30 FortiAuthenticator gui[1859] error fac.home.www-data.FastAPI.apps.saml.views.samlidp __init__ 140208609381248 SP Test assertion request error: 'NoneType' object has no attribute 'split' In the FortiAuthenticator, select Authentication -> SAML IdP -> Service Providers and check if the SP SLS (logout) URL is empty.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.