Issues with KeyCloak SAML2 SPs?

IAM David Bantz dabantz at alaska.edu
Wed Nov 26 21:21:45 UTC 2025


We set up SSO with a vendor that relies on KeyCloak as the SAML2 SP
interface. Are other users here aware of sporadic but plentiful failures
with similar set-up? If so, we're desperate for potential remedies to offer
to the vendor.

The iterative process to set up SAML2 SSO was frustrating as many aspects
of SAML practices were apparently unknown to the vendor. But we have a
seemingly complete integration in routine production. However many users -
both naive users and experienced skilled users reproducing students'
experiences - report failures at the service despite normal successful SSO
and SAML response from the IdP to SP. We have repeatedly copied the exact
SAML response (prior to encryption) to the vendor asking them to review
their own logs to determine why students were occasionally being stopped.
In some cases, a second or third sign-in attempt - seemingly identical to
failed attempts - succeeds. We've provided examples of the exact same SAML
response (save timestamps and transient nameID) that succeeds one time,
fails another. Responses to have been, essentially, expressions of
puzzlement; we have not seen any detailed logs from either KeyCloak or the
service being protected. We've been stuck in this loop for 6 weeks; this is
a mission critical service owned locally by our Registrars, who are
understandably frustrated and despondent and have inboxes flooded with
complaints from students unable to get needed service.

I did not mention the vendor or service to avoid flack, but will if it
helps; many of you would recognize them.

David St PIerre Bantz
UA IAM
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20251126/20927e2c/attachment.htm>


More information about the users mailing list