Cisco WebEx Meetings Server Troubleshooting Guide Release 1.1

The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.

Book Contents Book Contents Find Matches in This Book Log in to Save Content Available Languages Download Options

Book Title

Cisco WebEx Meetings Server Troubleshooting Guide Release 1.1

Single Sign-On

Results

Updated: February 8, 2013

Chapter: Single Sign-On

Chapter Contents

Single Sign-On

This section includes troubleshooting topics about single sign-on (SSO) issues.

SSO Fails After Completing Disaster Recovery Operation

Problem When a user completes a disaster recovery operation, SSO fails due to expired certificates. Possible Cause Existing SSO certificates were installed before the application was installed. Solution Reinstall SSO certificates after completing Disaster Recovery Operation. After you perform your restoration on the disaster recovery system, sign in to the Administration site and select Settings > Security > Certificate > SSL Certificate > Generate CSR .Under More Options , select Download CSR to download the generated CSR. Use the CSR to obtain a new SSL Certificate. Refer to the "Generating SSL Certificates" section of the Administration Guide for more information. Import your new SSL certificate by selecting Settings > Security > Certificate > More Options (Import SSL Certificate). Import the same SSL certificate into your ADFS (Active Directory Federation Service) for the site URL's relay party.

SSO Protocol Error

Problem You receive the error message, "SSO protocol error. Contact your administrator for further support." Possible Cause Your SSO administration site or IdP configuration contains errors. Possible Cause SSO is not enabled. Possible Cause Some or all of the required IdP attributes are not configured: firstname, lastname, email. Possible Cause The NameID parameter of your SAML is not set to email. Solution If you are unable to determine the cause of your SSO protocol error, generate a log and contact the Cisco TAC for further assistance. If you believe the cause is one of the above, make sure the required IdP attributes are configured and make sure the following IdP attributes are set to the user's email address: uid, SAML_SUBJECT..

SSO Redirection Has Failed

SSO Error Codes

The following table lists the SSO error codes.

Error Description Error Code
SSO protocol error 1
No user name found in SAML assertion 2
No user account found in the system 3
No X.509 certificate found in the system 4
Only POST request is supported 5
Incorrect SAML SSO POST data 6
The site is not allowed to use SSO 7
Incorrect X.509 certificate to validate SAML assertion 8
Loading configuration error 9
The value of NameQualifier does not match site URL 10
Unable to reach Assertion Party 11
Failed to resolve SAML Artifact 12
Invalid SAML assertion 13
Recipient does not match webex.com 14
X.509 certificate has expired 15
User account is locked 16
User account is expired 17
User account has been deactivated 18
SAML assertion is expired 19
SAML assertion is unsigned 20
User role is not allowed to login 21
Invalid RequestedSecurityToken 22
Invalid digital signature 23
Untrusted Issuer 24
Name Identifier format is incorrect 25
Unable to generate AuthnRequest 26
Unable to generate Logout Request 27
InResponseTo does not match the request ID 28
Invalid Response message 29
Invalid Request message 30
Auto Account Creation failed 31
Auto Account Update failed 32