Groups gives no access with SSO over SAML - Sonatype Lifecycle & Repository Firewall - Sonatype Community

Groups gives no access with SSO over SAML

post by christoffer.hafsahl on Aug 15, 2022

Christoffer Hafsahl
Hi all, I’ve gotten single-sign-on via SAML up and running, and also have the LDAP connection working as it should. I’m able to search for AD groups and assign a group to an organization in the IQ server, but for some reason a user who is member of that group has no access when logging in via SAML.

I’ve checked that the SAML claims are mapped correctly, but cannot get it to work. Assigning users to an organization works as expected however. Are there any common pitfalls I might have overlooked, or is it possible to configure the logging so that the groups coming from SAML are logged?

893 views

post by jeff.wise on Sep 7, 2022

Jeff Wise
There are various browser add-ons / plugins available for debugging SAML. Use one of these tools to ensure the SAML response contains the groups you expect. IQ receives the same response you see when using these SAML debugging tools.

Chrome – SAML Chrome Panel
Firefox – SAML Tracer

New & Unread Topics

Topic Replies Views Activity
how to use remote tcp socket instead of local unix socket for nexus iq container image scan for pulling neuvector image from private registry 1 65 Apr 21
Sonatype Firewall Pro now available for third-party users! 1 95 May 28
IQ Firewall: Database update frequency and coverage of new libraries against recent threats 4 39 Jun 9
Bom scan does not generate a report 3 122 Mar 11
How do I set up a proxy for this Maven2 repo? 5 112 Jan 29

Topic list, column headers with buttons are sortable.