Workspaces SAML SP Response Issue

0

I recently followed these instructions to set up SAML for AmazonWorkspaces. The result: a loop between 'Open Workspaces' and the IdP auth (which seems to be working fine). I looked at the URL details, and noticed that AWS (acting as SP) provides an SP response containing three URLs:

  • The IdP SSO URL (presumably taken from the metadata.
  • The relaystate URL created per the instructions.
  • A token (saml/start/TOKEN) to start the workspace.

When I copy/paste the third URL into the browser, it does successfully open the workspace login screen. This makes me think that the SP response needs to be edited so that only the third URL is provided. Any ideas how to do this?

I'm thinking the IdP metadata (I'm using Okta btw) needs to be edited somehow, though I'm open to other suggestions as well.

  • Did you ever find a solution? I am also getting the same loop.

1개 답변
0

If you're using Okta, you need to make sure you enter all the attributes specified in step 5 . The default application will not include all the attributes necessary. Nor is sAMAccountName an attribute that is available to most SAML 2.0 IdPs, which is why most need to follow the instructions in Okta for creating the custom attribute.

AWS
전문가
답변함 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인