Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Pedroso
New Contributor II

Error SAML Auth FortiOS 7.4.1

Hi Guys, I have a problem after update my FGT 200E to 7.4.1, my SAML auth was operating normally, now I can't loggin to administrate firewall, I already did a new configuration on FGT and Azure but I receive the same error.

 

"AADSTS7500525: There was an XML error in the SAML message at line 1, position 503. Verify that the XML content of the SAML messages conforms to the SAML protocol specifications."

 

Someone also had this error and know how to fix it ?

 

Tks

Anderson Almeida Pedroso
Anderson Almeida Pedroso
1 Solution
Pedroso
New Contributor II

I found the solution, @dbu your tip was helpful, but I show the path that I can resolve the problem:

Go to Settings, Fabric SSO

 

Screenshot 2023-10-14 174551.png

 

Click on "Security Fabric settings" and next "Advance Options"

Screenshot 2023-10-14 174728.png

 

Expand SP Details, you will notice that "SP entity ID" is blank

Screenshot 2023-10-14 175006.png

Insert your http ID, for example: http://fwtest.com:1111/metadata/

Now your SAML auth is working again.

 

 

Anderson Almeida Pedroso

View solution in original post

Anderson Almeida Pedroso
3 REPLIES 3
dbu
Staff
Staff

Hi @Pedroso ,
It looks like the entity id is set to empty for the SP in the Fortigate. 
Configure it manually from the CLI as it was before the upgrade. Check the backup file.


#config system saml
#set entity-id <SP entity ID>

#end

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Pedroso
New Contributor II

I was comparing the actual config version (7.4.1) with the bkp version (7.2.5), I noticed that the version had a "set artifact-resolution-url "https://x.x.x.x:xx/saml/?artifact", and new version there isn't this.

I already tried every thing.

Sad :\ 

Anderson Almeida Pedroso
Anderson Almeida Pedroso
Pedroso
New Contributor II

I found the solution, @dbu your tip was helpful, but I show the path that I can resolve the problem:

Go to Settings, Fabric SSO

 

Screenshot 2023-10-14 174551.png

 

Click on "Security Fabric settings" and next "Advance Options"

Screenshot 2023-10-14 174728.png

 

Expand SP Details, you will notice that "SP entity ID" is blank

Screenshot 2023-10-14 175006.png

Insert your http ID, for example: http://fwtest.com:1111/metadata/

Now your SAML auth is working again.

 

 

Anderson Almeida Pedroso
Anderson Almeida Pedroso
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors