Pain point · Permissions & security · Causes churn
SAML entityID overwritten by the callback URL
5 source threads · first seen 2018-10 · last seen 2025-02
Summary
A Keycloak SAML setup failed until the client ID was set to the callback URL, after hours of debugging.
- Affects
- admins configuring SAML
- Workaround
- Set the Keycloak client ID to the callback URL
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“After upgrading the V25 the SAML connection stopped working”
“when we upgraded to 10, everything works other than the SAML part”
“After many hours of debugging I've noticed that entityID for Saml authentication is replaced by callback URL:”
“I land at my redash domain and get a 500 Error”
“XML parse error: Signature missing for assertion”