Single Sign On (SSO): Troubleshooting

Prev Next

The following errors indicate you have hit the correct URL for SSO login and your entry is properly logged in the server SSO logs. Any errors received outside of this set indicate you are hitting an incorrect URL or attempts are not hitting our servers. This issue must be addressed by your IT team.

SSO-060 Certificate check failed

This error indicates multiple potential issues:

  • The clientID attribute included in the your SAML message is incorrect or missing. See white paper entry below regarding ClientID attribute:

    • Action Item: This attribute needs to be corrected / added into the SAML message by your IT team.

  • The actual attribute name for the clientID attribute has incorrect casing. SAML is case sensitive and must match the exact case of “clientID.”

    • Action Item: This attribute needs to be corrected by your IT team to set the case accordingly.

  • The Signature element of your SAML message is missing.

    • Action Item: The signature element should be in the root of the response element. Have your IT team make sure the SAML response in its entirety is signed, not any sub-elements. The response should elements follow this structure:

  • The certificate used to sign your SAML message is not the same certificate that was provided to DevOps for installation or the certificate installed has expired.

    • Action Item: Serial numbers of the certificate provided and the certificate in use will need to be compared. Review the certificates in use vs. what was provided to Ripple Treasury.  If you are unable to provide these certificates, talk to DevOps about potentially comparing certificates and check if the certificate is still valid.

  • You are using an incorrect encryption algorithm.

    • Action Item: Make sure you are using SHA256.

  • You are including an extra tag in the signature node, InclusiveNamespaces.

    • Action Item: Remove this item.  This is an unhandled tag by Microsoft and it should be dropped.

SSO-010 Incorrect request format

This error indicates multiple potential issues:

  • You attempted a login through a process that didn't send a SAML message to our URL. For example, you directly navigated to the SSO URL provided by Ripple Treasury, rather than using your SSO portal. You may be under the incorrect assumption that Ripple Treasury utilizes service provider (SP) initiated SSO and you should be navigating to the URL provided directly. Actually, Ripple Treasury utilizes identity provider (IDP) initiated SSO. See the following white paper entry:

    • Action Item: Make sure you are logging in through your SSO portal that is configured to send requests to the provided SSO URL.

  • Your attempted login hasn't been configured in one (or many) Ripple Treasury aspects, that is the operators are not checked to allow SSO, the certificate has not been installed, servers haven’t been configured, etc.

    • Action Item: Make sure SSO login is in your contract. If not, an account manager will need to update your contract via term sheet to include SSO login. If SSO is already included, make sure to follow up with the solutions/support team members that were involved in configuring your account for SSO. There could be missing materials such as a certification or application setup that needs to be completed. If all steps have been completed, see DevOps to review the SSO logs.

SSO-030 Incorrect request format for SSO login

This error indicates multiple potential issues:

  • Your attempted login is configured server side to use the new SSO functionality but is not properly configured in the application.

    • Action Item: Make sure the application is properly configured to use the new SSO functionality.

  • Your attempted login is configured server side to use the new SSO functionality, but the NameID passed in the subject section of the does not match the external ID in use for the new functionality.
    Deprecated Note: If the intention is to use email address as the external ID, currently Ripple Treasury SSO strips off the domain on an email address. Thus, if user.1@Ripple Treasury.com tried to log in, user.1 would need to be the external ID value. Per new release, email domains are no longer stripped off upon login request. Full email addresses can be used.

    • Action Item:  Make sure the external ID value and NameID of the SAML are matching correctly. May need to coordinate with your IT on this.

  • The NameID in the Subject section of the your SAML is completely missing.  See the following white paper entry:

    • Action Item: Your IT will need to revisit the way their SSO client is setup to make sure the NameID is coming through in the SAML.

SSO-070 Login failed (see log for details)

This error indicates multiple potential issues:

  • The NameID in the Subject section of your SAML message doesn't match an operator ID in Ripple Treasury. See the following white paper entry:

    • Action Item: You need to adjust your SAML message so the NameID matches a Ripple Treasury operator.

  • Login was attempted by a user that does not exist in Ripple Treasury (i.e., an IT resource that will never have a Ripple Treasury operator ID).

    • Action Item: Make sure login attempts are made by operators that have Ripple Treasury operator IDs.

  • Login was attempted by a user with a Ripple Treasury operator ID, but the “Allow SSO Login” box is not marked for this user.

    • Action Item: Make sure this box is checked for all users intending to use SSO.


FAQ

SSO-010 Incorrect request format

The client attempted a login through a process that did not send a SAML message to our URL or the client attempted login and has misconfigured.

  1. Make sure the user is logging in through their company’s SSO portal and not directly to Ripple Treasury.

  2. Confirm all steps have been completed in this documentation.

  3. Review the certificate has been passed to Ripple Treasury and has been installed.

  4. Ensure SSO is purchased and enabled for your company (GT Account Management).

  5. Engage GT Support with the result of 1-3 above.

SSO-030 Incorrect request format for SSO login

This error indicates a few potential issues:

  • The client attempting to login is configured server side to use the new SSO functionality but is not properly configured in the application.

    • Action Item: Make sure the application is properly configured for the client to use the new SSO functionality.

  • The client attempting to login is configured server side to use the new SSO functionality, but the user.userprincipalname passed in the subject section of the does not match the “Identity Token Value” in use for the new functionality.

    • Action Item: Make sure the external ID value and user.userprincipalname of the SAML are matching correctly. May need to coordinate with client IT on this.

  • The user.userprincipalname in the Subject section of the client’s SAML is completely missing.

    • Action Item: Client IT will need to revisit the way their SSO client is setup to make sure the user.userprincipalname is coming through in the SAML.

SSO-060 Certificate check failed

This error indicates 2 potential issues:

  • The ClientID attribute included in the client’s SAML message is incorrect or missing.

    • Action Item: This attribute needs to be corrected/added into the SAML message by the client’s IT team.

  • The certificate used to sign the client’s SAML message is not the same certificate that was provided to Ripple Treasury and is configured and installed on the server.

    • Action item: Serial numbers of the certificate provided and the certificate in use will need to be compared. Clients should review the certificates in use vs. what was provided to Ripple Treasury.

SSO-070 Login failed

This error indicates 3 potential issues:

  • The user.userprincipalname in the Subject section of the client’s SAML message does not match an operator ID in Ripple Treasury.

    • Action Item: The client needs to adjust their SAML message so the user.userprincipalname matches a Ripple Treasury operator.

  • Login was attempted by a user that does not exist in Ripple Treasury (i.e. an IT resource that will never have a GT operator ID).

    • Action Item: Make sure login attempts are made by operators that have GT operator IDs.

  • Login was attempted by a user with a Ripple Treasury operator ID, but the “Allow SSO Login” box is not checked for this user.

    • Action Item: Make sure this box is checked for all users intending to use SSO.