<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;500 - Internal server error&amp;quot; when using SHA-256 in SAML authentication in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1527987#M12237</link>
    <description>Thank you!! Looking forward to hear the result &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
    <pubDate>Tue, 08 Jan 2019 18:01:14 GMT</pubDate>
    <dc:creator>Bastien_Laugiero</dc:creator>
    <dc:date>2019-01-08T18:01:14Z</dc:date>
    <item>
      <title>"500 - Internal server error" when using SHA-256 in SAML authentication</title>
      <link>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1527146#M12214</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get a 500 Internal Server Error from Qlik Sense, September 2018 version, when using SHA-256, instead of the default SHA-1 as signing algorithm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The error message in 'Proxy\TESTPUB02_Audit_Proxy.txt' is:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;WARN testpub02 Audit.Proxy.Proxy.Core.RequestListener 152 973a2763-e18c-4e5a-8a23-210989e0e9d8 TESTPUB02\user Unanticipated ComponentSpace.SAML2.Exceptions.SAMLSignatureException occurred for connection&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My settings are:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SOTEST Virtual Proxy.png" style="width: 699px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/3176iB2E655D3A3D31C2C/image-size/large?v=v2&amp;amp;px=999" role="button" title="SOTEST Virtual Proxy.png" alt="SOTEST Virtual Proxy.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I go to &lt;A href="https://my.public.url/sotest" target="_blank"&gt;https://my.public.url/sotest&lt;/A&gt;, I get a redirect to&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://my.public.url/sotest/hub/" target="_blank"&gt;https://my.public.url/sotest/hub/&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The hub returns a 500 Internal server error after just 5 ms.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I choose SHA-1, I get redirected to the Google login.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;According to &lt;A href="https://community.qlik.com/thread/217948" target="_self"&gt;this post&lt;/A&gt;, the certificate used for the Qlik Proxy needs to support SHA-256 XML signatures.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Our certificate says it's signing algorithm is 'sha256RSA'.&amp;nbsp;&amp;nbsp;Is that not good enough?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SOTEST Certificate.png" style="width: 386px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/3178i779D4D6DBAF5AC2C/image-size/large?v=v2&amp;amp;px=999" role="button" title="SOTEST Certificate.png" alt="SOTEST Certificate.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any tip is appreciated,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Vegard&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2024 06:55:18 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1527146#M12214</guid>
      <dc:creator>vegard_bakke</dc:creator>
      <dc:date>2024-11-16T06:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: "500 - Internal server error" when using SHA-256 in SAML authentication</title>
      <link>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1527165#M12215</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Looking at the error from the Audit logs it seems that the certificate does not have the correct Cryptographic Provider set.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In order to use SHA-256 in Qlik Sense with SAML, the cryptographic provider for the certificate applied on the Qlik Sense proxy must be "&lt;/SPAN&gt;&lt;SPAN&gt;Microsoft Enhanced RSA and AES Cryptographic Provider".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Here is&amp;nbsp;&lt;A href="https://qliksupport.force.com/articles/000041560" target="_self"&gt;an article&lt;/A&gt; referring to the error message.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And here is &lt;A href="https://qliksupport.force.com/articles/000041680" target="_self"&gt;an article&lt;/A&gt; providing the steps to check and change the&amp;nbsp;cryptographic provider&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 15:37:49 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1527165#M12215</guid>
      <dc:creator>Bastien_Laugiero</dc:creator>
      <dc:date>2019-01-07T15:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: "500 - Internal server error" when using SHA-256 in SAML authentication</title>
      <link>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1527804#M12235</link>
      <description>&lt;P&gt;Thank you so much for you quick reply. I will check out this, and give you some feedback. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2019 14:05:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1527804#M12235</guid>
      <dc:creator>vegard_bakke</dc:creator>
      <dc:date>2019-01-08T14:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: "500 - Internal server error" when using SHA-256 in SAML authentication</title>
      <link>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1527987#M12237</link>
      <description>Thank you!! Looking forward to hear the result &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Tue, 08 Jan 2019 18:01:14 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1527987#M12237</guid>
      <dc:creator>Bastien_Laugiero</dc:creator>
      <dc:date>2019-01-08T18:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: "500 - Internal server error" when using SHA-256 in SAML authentication</title>
      <link>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1529019#M12251</link>
      <description>&lt;P&gt;I've tried a few different things now.&amp;nbsp; All give the same results, unfortunately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have one self-signed certificate for the testpub02.company.com, and one for *.company.com.&lt;/P&gt;&lt;P&gt;I have added the "&lt;STRONG&gt;Microsoft Enhanced RSA and AES Cryptographic Provider&lt;/STRONG&gt;" using openssl as described in your second link.&amp;nbsp; (cert&lt;/P&gt;&lt;P&gt;I have set up one Qlik virtual proxy with our local IdP-metadata, and one virtual proxy using IdP-metadata for Google Accounts. (The certutil.exe -dump now reports&amp;nbsp;&lt;STRONG&gt;Provider = Microsoft Enhanced RSA and AES Cryptographic Provider&lt;/STRONG&gt;.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Going to the "Google IdP prefix", I get immediately redirected to the Google login page.&lt;BR /&gt;But using the #local IdP prefix" still gives 500&amp;nbsp;Internal server error.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the error message is still:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;WARN testpub02 Audit.Proxy.Proxy.Core.RequestListener TESTPUB02\user Unanticipated ComponentSpace.SAML2.Exceptions.SAMLBindingException occurred for connection&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anywhere I can get a more detailed error message?&amp;nbsp; Or any logging I can turn on?&lt;/P&gt;&lt;P&gt;How can I find out what is actually going wrong? I looks like it might be something wrong with our metadata. But how to identify what it is, beats me... &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vegard&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 13:59:05 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1529019#M12251</guid>
      <dc:creator>vegard_bakke</dc:creator>
      <dc:date>2019-01-10T13:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: "500 - Internal server error" when using SHA-256 in SAML authentication</title>
      <link>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1529090#M12253</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Thank you for applying the article. So the error has now changed.&lt;/P&gt;
&lt;P&gt;In the beginning, it was: Unanticipated ComponentSpace.SAML2.Exceptions.&lt;STRONG&gt;SAMLSignatureException&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;And now: Unanticipated ComponentSpace.SAML2.Exceptions.&lt;STRONG&gt;SAMLBindingException&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This new error is related to the fact that your Idp metadata has been created with the binding method HTTP POST instead of HTTP REDIRECT.&lt;BR /&gt;Every information is documented &lt;A href="https://qliksupport.force.com/articles/000045712" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 17:31:15 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1529090#M12253</guid>
      <dc:creator>Bastien_Laugiero</dc:creator>
      <dc:date>2019-01-10T17:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: "500 - Internal server error" when using SHA-256 in SAML authentication</title>
      <link>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1529199#M12256</link>
      <description>&lt;P&gt;Thank you! I didn't notice that the exception was indeed different. And thank you for the link.&lt;/P&gt;&lt;P&gt;I will look into this on Monday.&lt;/P&gt;&lt;P&gt;cheers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 21:12:13 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1529199#M12256</guid>
      <dc:creator>vegard_bakke</dc:creator>
      <dc:date>2019-01-10T21:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: "500 - Internal server error" when using SHA-256 in SAML authentication</title>
      <link>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1530064#M12270</link>
      <description>Thank you so much Bastien! Our test IdP was not enabled for HTTP-Redirect.&lt;BR /&gt;&lt;BR /&gt;Maybe not the easiest error messages to decode. But now at least the community forum contains the error messages and links to the Qlik Support Knowledge articles, for others at a later stage.&lt;BR /&gt;&lt;BR /&gt;A little more can be found here:&lt;BR /&gt;&lt;A href="https://qliksupport.force.com/QS_CoveoSearch#q=ComponentSpace.SAML2&amp;amp;t=All&amp;amp;sort=relevancy" target="_blank"&gt;https://qliksupport.force.com/QS_CoveoSearch#q=ComponentSpace.SAML2&amp;amp;t=All&amp;amp;sort=relevancy&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Again, thank you so much! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Mon, 14 Jan 2019 14:57:09 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1530064#M12270</guid>
      <dc:creator>vegard_bakke</dc:creator>
      <dc:date>2019-01-14T14:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: "500 - Internal server error" when using SHA-256 in SAML authentication</title>
      <link>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1530085#M12271</link>
      <description>Thank you! &lt;BR /&gt;Glad it could be resolved &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Mon, 14 Jan 2019 15:16:18 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/quot-500-Internal-server-error-quot-when-using-SHA-256-in-SAML/m-p/1530085#M12271</guid>
      <dc:creator>Bastien_Laugiero</dc:creator>
      <dc:date>2019-01-14T15:16:18Z</dc:date>
    </item>
  </channel>
</rss>

