# SAML 1.8.0 error on log on

**URL:** https://community.xibo.org.uk/t/saml-1-8-0-error-on-log-on/9774
**Category:** Get Help
**Created:** [April 26, 2017, 3:08pm UTC](https://community.xibo.org.uk/t/saml-1-8-0-error-on-log-on/9774 "2017-04-26T15:08:56Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![stevieb](https://community.xibo.org.uk/letter_avatar_proxy/v4/letter/s/d07c76/32.png) [@stevieb](https://community.xibo.org.uk/u/stevieb)
#### Post date: [April 26, 2017, 3:08pm UTC](https://community.xibo.org.uk/t/saml-1-8-0-error-on-log-on/9774/1 "2017-04-26T15:08:57Z")

</div>

Hi All,

I’m testing SAML authentication and I’m getting a generic error message: “Unexpected Error, please contact support.” Since I’m using docker, I do not really know how to check any logs dealing with the issue. Any advice?

---

<div class="post-metadata">

### Author: ![Peter](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/peter/32/8154_2.png) [@Peter](https://community.xibo.org.uk/u/Peter)
#### Post date: [April 27, 2017, 10:19am UTC](https://community.xibo.org.uk/t/saml-1-8-0-error-on-log-on/9774/2 "2017-04-27T10:19:05Z")

</div>

Could you please let me know if you’ve followed the instructions here [http://xibo.org.uk/manual-tempel/en/users\_saml.html](http://xibo.org.uk/manual-tempel/en/users_saml.html) ?

We do have one CMS Instance in our cloud that we use for testing saml (it authenticates with our gmail email accounts) and that seems to work fine in 1.8.1.

As for logs, you could check CMS logs for more details - perhaps put your CMS in test mode as well.

---

<div class="post-metadata">

### Author: ![stevieb](https://community.xibo.org.uk/letter_avatar_proxy/v4/letter/s/d07c76/32.png) [@stevieb](https://community.xibo.org.uk/u/stevieb)
#### Post date: [April 27, 2017, 8:55pm UTC](https://community.xibo.org.uk/t/saml-1-8-0-error-on-log-on/9774/3 "2017-04-27T20:55:32Z")

</div>

Hi Peter,

Yes. I’m using Shibboleth for my IdP and I am being passed the following: givenname, email, PrincipalName and uid as attributes. My next question is does it matter if I keep ‘usertypeid’ blank in the mapping field?

---

<div class="post-metadata">

### Author: ![stevieb](https://community.xibo.org.uk/letter_avatar_proxy/v4/letter/s/d07c76/32.png) [@stevieb](https://community.xibo.org.uk/u/stevieb)
#### Post date: [April 27, 2017, 9:03pm UTC](https://community.xibo.org.uk/t/saml-1-8-0-error-on-log-on/9774/4 "2017-04-27T21:03:33Z")

</div>

I turn on logging and found this:

SAML SSO failed: invalid\_response. Last Reason: The status code of the Response was not Success, was Requester -\> An error occurred. Exception Type: OneLogin\_Saml2\_Error

What should be my next steps?

---

<div class="post-metadata">

### Author: ![dan](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/dan/32/9115_2.png) [@dan](https://community.xibo.org.uk/u/dan)
#### Post date: [April 28, 2017, 8:21am UTC](https://community.xibo.org.uk/t/saml-1-8-0-error-on-log-on/9774/5 "2017-04-28T08:21:02Z")

</div>

I think that means the URL you have in your SAML configuration - i.e. your IdP - didn’t return a successful response. Can you double check the URL’s you’ve entered there for correctness?

Edit: Actually I dont think that is correct - I believe the document is being returned by your IdP, but the status code attribute is set to `urn:oasis:names:tc:SAML:2.0:status:Requester` with the message ‘An error occurred’

Is there any logging on the SAML side that might provide some insight?

---

<div class="post-metadata">

### Author: ![stevieb](https://community.xibo.org.uk/letter_avatar_proxy/v4/letter/s/d07c76/32.png) [@stevieb](https://community.xibo.org.uk/u/stevieb)
#### Post date: [April 28, 2017, 8:06pm UTC](https://community.xibo.org.uk/t/saml-1-8-0-error-on-log-on/9774/6 "2017-04-28T20:06:42Z")

</div>

ok, so it seems that NameFormatId variable needed to be set SAML:1.1 instead of 2.0. But now I’m getting a different error:

SAML SSO failed: invalid\_response. Last Reason: Signature validation failed. SAML Response rejected Exception Type: OneLogin\_Saml2\_Error

So back to the logs I go.

---

<div class="post-metadata">

### Author: ![dan](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/dan/32/9115_2.png) [@dan](https://community.xibo.org.uk/u/dan)
#### Post date: [April 29, 2017, 8:55am UTC](https://community.xibo.org.uk/t/saml-1-8-0-error-on-log-on/9774/7 "2017-04-29T08:55:36Z")

</div>

> [@stevieb](#):
>
> So back to the logs I go.

Sorry!!

That error would indicate that the response from the IdP did not match the expected specification. There is a validation tool you can use (if you can capture the response) here: [Validate SAML XML Using XML Schema (XSD) - Validate XML Against XSD Online Tool](https://www.samltool.com/validate_xml.php)

---

<div class="post-metadata">

### Author: ![stevieb](https://community.xibo.org.uk/letter_avatar_proxy/v4/letter/s/d07c76/32.png) [@stevieb](https://community.xibo.org.uk/u/stevieb)
#### Post date: [May 10, 2017, 8:33pm UTC](https://community.xibo.org.uk/t/saml-1-8-0-error-on-log-on/9774/8 "2017-05-10T20:33:53Z")

</div>

So it looks like now I have an error message of “No attributes could be mapped”. All fields in the mapping variable are full but the usertypeid. Any thoughts?

---

<div class="post-metadata">

### Author: ![system](https://community.xibo.org.uk/uploads/default/original/2X/a/a8759c2d8cc561474733895ac75beeb830f5d8ca.png) [@system](https://community.xibo.org.uk/u/system)
#### Post date: [March 4, 2020, 5:07pm UTC](https://community.xibo.org.uk/t/saml-1-8-0-error-on-log-on/9774/9 "2020-03-04T17:07:15Z")

</div>


