<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multi-Node SAML with SSL - Isolate users to Engine nodes in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427299#M11248</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Definitely it helped, the mappings I was using were wrong, it was much more simpler!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Nov 2017 19:30:54 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2017-11-10T19:30:54Z</dc:date>
    <item>
      <title>Multi-Node SAML with SSL - Isolate users to Engine nodes</title>
      <link>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427294#M11243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some details first:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;We have a multi-node site on Qlik Sense September 2017 consisting of 1 central node and 1 engine node in shared persistence.&lt;/LI&gt;&lt;LI&gt;We are using auth0 SSO SAML for Authentication using a virtual proxy that's linked to the central node.&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The Auth0 callback is pointing to &lt;/SPAN&gt;&lt;A _jive_internal="true" href="https://community.qlik.com/" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;dns&amp;gt;:443/&amp;lt;proxy&amp;gt;/samlauthn/&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;The Virtual Proxy SAML Host URI and entity ID are both the DNS name.&lt;/LI&gt;&lt;LI&gt;We have our SSL certificate and DNS configured and pointed towards the central node.&lt;/LI&gt;&lt;LI&gt;The Central Node host is the DNS name (not the machine name or IP address).&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Ideally we would send users to only the Engine node after authentication through the virtual proxy (not load balancing with the central), currently they are only using the Central node and nobody has ever hit the Engine.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;When I link the virtual proxy to the Central node, and load balance with &lt;SPAN style="text-decoration: underline;"&gt;only&lt;/SPAN&gt; the Engine, I get the auth0 login which is great. I then log in and get 'The service did not respond or could not process the request'. This error does NOT occur when I load balance with the Central node only.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reading &lt;A href="http://help.qlik.com/en-US/sense/September2017/Subsystems/ManagementConsole/Content/configure-load-balance-to-isolate-development-nodes.htm" title="http://help.qlik.com/en-US/sense/September2017/Subsystems/ManagementConsole/Content/configure-load-balance-to-isolate-development-nodes.htm"&gt;Configuring load balancing to isolate development nodes ‒ Qlik Sense&lt;/A&gt;‌ makes me believe we can have the Virtual Proxy linked to the Central node but how in the world do I send users to only the Engine?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't figure it out! &lt;STRONG&gt;Do I do this with load balancing rules?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Oct 2017 04:10:37 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427294#M11243</guid>
      <dc:creator>balexbyrd</dc:creator>
      <dc:date>2017-10-25T04:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-Node SAML with SSL - Isolate users to Engine nodes</title>
      <link>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427295#M11244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like I'm getting a 500 error (internal server error) at /api/hub/about&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've removed IPV6 from the engine node&lt;/P&gt;&lt;P&gt;I've fully uninstalled the Engine node, removing the certificates and relinking.&lt;/P&gt;&lt;P&gt;I've restarted the services&lt;/P&gt;&lt;P&gt;I've made sure the ports are open between the Central &amp;amp; Engine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What else is left?!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Found other users in similar situations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.qlik.com/thread/260489"&gt;Qlik Sense Multi-nodes site guidance&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.qlik.com/thread/276815"&gt;Qlik Sense and Webseal - header authentication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="180951" alt="Error 500.PNG" class="jive-image image-1" src="/legacyfs/online/180951_Error 500.PNG" style="height: 314px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="180952" alt="Error 500 2.PNG" class="jive-image image-2" src="/legacyfs/online/180952_Error 500 2.PNG" style="height: 215px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="180968" alt="Error 500 3.PNG" class="jive-image image-3" src="/legacyfs/online/180968_Error 500 3.PNG" style="height: 365px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2017 01:26:57 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427295#M11244</guid>
      <dc:creator>balexbyrd</dc:creator>
      <dc:date>2017-10-26T01:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-Node SAML with SSL - Isolate users to Engine nodes</title>
      <link>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427296#M11245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've tested this with Ticket &amp;gt; Windows Authentication and get the same result&lt;/P&gt;&lt;P&gt;I've tested this with Google Chrome and Internet Explorer and get the same result&lt;/P&gt;&lt;P&gt;I've test this with all of the services running on the Engine node and get the same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This has to be bug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logged a ticket with support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Oct 2017 01:01:36 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427296#M11245</guid>
      <dc:creator>balexbyrd</dc:creator>
      <dc:date>2017-10-31T01:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-Node SAML with SSL - Isolate users to Engine nodes</title>
      <link>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427297#M11246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am pretty interested on how you set up Qlik with Auth0. I have been trying to do something similar, but I am getting a "SAML attribute not present, userID" error constantly. I guess that I am not mapping the userID value from Auth0 correctly. In the SAML configuration I have tried to do something like the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"recipient" : &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;..............&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"destination" : &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;...............&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;"mappings" : {&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "userID" : "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://schemas.auth0.com/nickname" rel="nofollow" target="_blank"&gt;http://schemas.auth0.com/nickname&lt;/A&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How did you get this Qlik-Auth0 connection to work? I will really appreciate if you can share some hints about the process you followed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2017 22:25:37 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427297#M11246</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2017-11-07T22:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-Node SAML with SSL - Isolate users to Engine nodes</title>
      <link>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427298#M11247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Carlos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're using auth0 with an email . So in the virtual proxy &amp;gt; SAML attribute for user id we have 'uid'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's a snip from our settings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; "mappings": {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "email": "uid"&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Qlik&lt;/P&gt;&lt;P&gt;&lt;IMG alt="auth0.PNG" class="jive-image image-1" src="https://community.qlik.com/legacyfs/online/182890_auth0.PNG" style="height: 408px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Auth0&lt;/P&gt;&lt;P&gt;&lt;IMG alt="auth02.PNG" class="jive-image image-2" src="https://community.qlik.com/legacyfs/online/182893_auth02.PNG" style="height: 113px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this help?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 16:59:21 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427298#M11247</guid>
      <dc:creator>balexbyrd</dc:creator>
      <dc:date>2017-11-10T16:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-Node SAML with SSL - Isolate users to Engine nodes</title>
      <link>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427299#M11248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Definitely it helped, the mappings I was using were wrong, it was much more simpler!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 19:30:54 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Multi-Node-SAML-with-SSL-Isolate-users-to-Engine-nodes/m-p/1427299#M11248</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2017-11-10T19:30:54Z</dc:date>
    </item>
  </channel>
</rss>

