Issues with KeyCloak SAML2 SPs?
IAM David Bantz
dabantz at alaska.edu
Thu Nov 27 01:06:27 UTC 2025
Thank you for the response.
Our IdP side uses sticky sessions and I can verify that the successful and
unsuccessful sign-ins for the same user were issues from the same IdP node.
But when we next meet, I will raise that issue for the vendor to examine on
the SP side.
David Bantz
On Wed, Nov 26, 2025 at 3:13 PM o haya <ohaya1001 at gmail.com> wrote:
> Hi,
> Is there any clustering/round robin going on in the path somewhere? That
> might explain why you are seeing problems intermittently?
>
> On Wed, Nov 26, 2025 at 4:22 PM IAM David Bantz via users <
> users at shibboleth.net> wrote:
>
>> We set up SSO with a vendor that relies on KeyCloak as the SAML2 SP
>> interface. Are other users here aware of sporadic but plentiful failures
>> with similar set-up? If so, we're desperate for potential remedies to offer
>> to the vendor.
>>
>> The iterative process to set up SAML2 SSO was frustrating as many aspects
>> of SAML practices were apparently unknown to the vendor. But we have a
>> seemingly complete integration in routine production. However many users -
>> both naive users and experienced skilled users reproducing students'
>> experiences - report failures at the service despite normal successful SSO
>> and SAML response from the IdP to SP. We have repeatedly copied the exact
>> SAML response (prior to encryption) to the vendor asking them to review
>> their own logs to determine why students were occasionally being stopped.
>> In some cases, a second or third sign-in attempt - seemingly identical to
>> failed attempts - succeeds. We've provided examples of the exact same SAML
>> response (save timestamps and transient nameID) that succeeds one time,
>> fails another. Responses to have been, essentially, expressions of
>> puzzlement; we have not seen any detailed logs from either KeyCloak or the
>> service being protected. We've been stuck in this loop for 6 weeks; this is
>> a mission critical service owned locally by our Registrars, who are
>> understandably frustrated and despondent and have inboxes flooded with
>> complaints from students unable to get needed service.
>>
>> I did not mention the vendor or service to avoid flack, but will if it
>> helps; many of you would recognize them.
>>
>> David St PIerre Bantz
>> UA IAM
>>
>> --
>> For Consortium Member technical support, see
>> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20251126/5674aa6e/attachment.htm>
More information about the users
mailing list