Symantec IGA

 View Only

  • 1.  Vapp - Identity Portal v14.5 SAML sign-on error when enable with Encrypt SAML Assertion

    Posted Jan 05, 2026 04:29 AM

    Hi All,

    I am using Vapp 14.5 with IP, where IP is enabled with single-sign-on using SAML integration to my Idp. My Idp is keycloak v26.

    Firstly, IP is able to integrate with my Idp(keycloak), using no encryption assertion. 

    Next, I uploaded a new certificate into IP, and changed Request Decryption key to use this new cert. Save the setting and perform export SP metadata.

    Then i take this SP metadata and load into my Idp(keycloak)-clients. Setting is loaded correctly with the same new cert.

    Next when i test login sigma page, it able to redirect my Idp Login page, so i sign-in with username & password. After that page show error.

    When i check the IP log, i saw this error Exception occured in verifySamlResponseSignature Verification failed.

    On the SAML Tracer, i have this result.

    Anyone have faced this issue before ?  

    regards,

    William



    -------------------------------------------


  • 2.  RE: Vapp - Identity Portal v14.5 SAML sign-on error when enable with Encrypt SAML Assertion

    Broadcom Employee
    Posted Jan 06, 2026 01:30 AM

    Hi William,

    The Export SP metadata will not export the above certificate that you created.

    You need to manually export and import this certificate into your IDP and configure the same for encrytion.

    Thanks,

    Yogitha.

    -------------------------------------------



  • 3.  RE: Vapp - Identity Portal v14.5 SAML sign-on error when enable with Encrypt SAML Assertion

    Posted Jan 06, 2026 02:15 AM

    Hi Yogitha,

    I have checked my Idp, the cert for encryption is loaded correctly.

    I have some new finding, in my Idp_clientSP setting by default these 2 setting is turn on Sign document & Sign Assertion.

    If i turn off both setting, then my SP decryption works(user able to login). 

    It seems like when SAML Assertion Encryption is turn on together with sign documents=on and sign assertion=on, IdentityPortal login doesnt work.

    As per my understanding modern Idp & Sp SAML integration works together when all 3 -> assertion encryption is ON, sign document is ON and sign assertion is ON. 

    regards,

    William

    -------------------------------------------



  • 4.  RE: Vapp - Identity Portal v14.5 SAML sign-on error when enable with Encrypt SAML Assertion

    Broadcom Employee
    Posted Jan 06, 2026 10:25 AM

    No customer reported this issue as of now. It supposed to work.

    Can you enable only sign assertions and check whether it's working or not.

    If problem persists, open a support ticket.

    Thanks,

    Chendra.

    -------------------------------------------



  • 5.  RE: Vapp - Identity Portal v14.5 SAML sign-on error when enable with Encrypt SAML Assertion

    Posted Jan 06, 2026 06:37 PM
    Edited by William Cheang Jan 06, 2026 10:32 PM

    Hi Chendra,

    i have open ticket below:

    80041632 -IdentityPortal(SP) integrated using SAML - when Request Decryption key turn on, Portal login not working.

    Will try with sign assertion only together with encrypt assertion.

    FYI. I noticed other IDPs is providing this SAML option. where Signing is either Assertion or Response, there is no both option.

    regards,

    William

    -------------------------------------------



  • 6.  RE: Vapp - Identity Portal v14.5 SAML sign-on error when enable with Encrypt SAML Assertion

    Broadcom Employee
    Posted Jan 08, 2026 01:15 AM
    Are you sure that you uploaded the SP public to your IDP(keycloak) and set
    the same key for the encryption?

    --

    Regards*,*

    *Chendra Shekar Gadangi*

    Identity Governance & Administration

    *Broadcom*

    *mobile:* +91 994 966 9823




  • 7.  RE: Vapp - Identity Portal v14.5 SAML sign-on error when enable with Encrypt SAML Assertion

    Posted Jan 08, 2026 01:49 AM

    Hi Chendra,

    This is the exported IP-SPMetadata.xml file from IdentityPortal

    It contain certificate info and the tag use=encryption

    After import this IP-SPmetadata.xml into my keycloak SAML – Client, the encrypt assertion on is auto turn on and loaded with certificate, which is the same cert.

    regards,

    William

    -------------------------------------------



  • 8.  RE: Vapp - Identity Portal v14.5 SAML sign-on error when enable with Encrypt SAML Assertion

    Posted Jan 07, 2026 08:10 PM

    Hi Chendra,

    I have tested with enable only sign assertion together with encrypt assertions, and the sigma portal login works.

    It seems like, SAML integration does not work when encrypt assertion is enabled together with sign documents feature.

    regards,

    William

    -------------------------------------------