<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Qlik Sense and SAML setup for Google auth - 500 error in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-and-SAML-setup-for-Google-auth-500-error/m-p/91323#M1517</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope someone can help me here as I am trying to get Sense hooked up with SAML with Google for SSO authentication.&lt;/P&gt;&lt;P&gt;I have followed the instructions from Eric Clutario&lt;SPAN style="color: #8b8b8b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px;"&gt; &lt;/SPAN&gt;&lt;A href="https://community.qlik.com/docs/DOC-17021"&gt;Google-QlikSAMLSSO.pdf&lt;/A&gt; as well as watched the youtube videos on SAML setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that I have managed to get authentication from Google apps, once authenticated in Google choosing the QlikSense app authenticates perfectly, authenticating and creating the user in Sense great i.e. &lt;SPAN style="background-color: #f6d5d9;"&gt;see &lt;/SPAN&gt;below:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.PNG" class="jive-image image-1" height="187" src="https://community.qlik.com/legacyfs/online/212614_Capture.PNG" style="height: 187.547px; width: 77px;" width="77" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, if I go straight to the SSO virtual proxy in Sense i.e. &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt;server&amp;gt;&lt;/SPAN&gt;&lt;/EM&gt;/sso/hub I get a 500 error, almost like it cannot get to the Google SSO URL or is being bounced, see the error, I would have expected to see the google auth prompt:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture2.PNG" class="jive-image image-2" height="285" src="https://community.qlik.com/legacyfs/online/212618_Capture2.PNG" style="height: 285px; width: 597.845px;" width="598" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked the logs on the server and cannot find any reference to the error, a warning or info on it, so I am thinking it is outside of the engine or proxy, or the IdP metadata is incorrect, but this is what I downloaded from the certificate in the Google Admin App location. &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;See setting from the QMC below, I have tried SHA-256 and SHA-1, updating the IdP metadata and this seems all fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture3.PNG" class="jive-image image-3" src="https://community.qlik.com/legacyfs/online/212619_Capture3.PNG" style="height: 349px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;And see the Google App setup from the admin screen as per Eric's instructions:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture4.PNG" class="image-4 jive-image" src="https://community.qlik.com/legacyfs/online/212620_Capture4.PNG" style="height: 506px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture5.PNG" class="image-5 jive-image" src="https://community.qlik.com/legacyfs/online/212621_Capture5.PNG" style="height: 126px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the IdP metadata that I am using from Google which has been loaded into the proxy. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture6.PNG" class="jive-image image-6" height="191" src="https://community.qlik.com/legacyfs/online/212622_Capture6.PNG" style="height: 191.113px; width: 697px;" width="697" /&gt;&lt;/P&gt;&lt;P&gt;So I am now at a loss on why this is not working, any help would be a great help and I am now stuck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Sep 2018 14:51:32 GMT</pubDate>
    <dc:creator>lee_connor</dc:creator>
    <dc:date>2018-09-04T14:51:32Z</dc:date>
    <item>
      <title>Qlik Sense and SAML setup for Google auth - 500 error</title>
      <link>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-and-SAML-setup-for-Google-auth-500-error/m-p/91323#M1517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope someone can help me here as I am trying to get Sense hooked up with SAML with Google for SSO authentication.&lt;/P&gt;&lt;P&gt;I have followed the instructions from Eric Clutario&lt;SPAN style="color: #8b8b8b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px;"&gt; &lt;/SPAN&gt;&lt;A href="https://community.qlik.com/docs/DOC-17021"&gt;Google-QlikSAMLSSO.pdf&lt;/A&gt; as well as watched the youtube videos on SAML setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that I have managed to get authentication from Google apps, once authenticated in Google choosing the QlikSense app authenticates perfectly, authenticating and creating the user in Sense great i.e. &lt;SPAN style="background-color: #f6d5d9;"&gt;see &lt;/SPAN&gt;below:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.PNG" class="jive-image image-1" height="187" src="https://community.qlik.com/legacyfs/online/212614_Capture.PNG" style="height: 187.547px; width: 77px;" width="77" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, if I go straight to the SSO virtual proxy in Sense i.e. &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt;server&amp;gt;&lt;/SPAN&gt;&lt;/EM&gt;/sso/hub I get a 500 error, almost like it cannot get to the Google SSO URL or is being bounced, see the error, I would have expected to see the google auth prompt:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture2.PNG" class="jive-image image-2" height="285" src="https://community.qlik.com/legacyfs/online/212618_Capture2.PNG" style="height: 285px; width: 597.845px;" width="598" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked the logs on the server and cannot find any reference to the error, a warning or info on it, so I am thinking it is outside of the engine or proxy, or the IdP metadata is incorrect, but this is what I downloaded from the certificate in the Google Admin App location. &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;See setting from the QMC below, I have tried SHA-256 and SHA-1, updating the IdP metadata and this seems all fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture3.PNG" class="jive-image image-3" src="https://community.qlik.com/legacyfs/online/212619_Capture3.PNG" style="height: 349px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;And see the Google App setup from the admin screen as per Eric's instructions:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture4.PNG" class="image-4 jive-image" src="https://community.qlik.com/legacyfs/online/212620_Capture4.PNG" style="height: 506px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture5.PNG" class="image-5 jive-image" src="https://community.qlik.com/legacyfs/online/212621_Capture5.PNG" style="height: 126px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the IdP metadata that I am using from Google which has been loaded into the proxy. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture6.PNG" class="jive-image image-6" height="191" src="https://community.qlik.com/legacyfs/online/212622_Capture6.PNG" style="height: 191.113px; width: 697px;" width="697" /&gt;&lt;/P&gt;&lt;P&gt;So I am now at a loss on why this is not working, any help would be a great help and I am now stuck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2018 14:51:32 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-and-SAML-setup-for-Google-auth-500-error/m-p/91323#M1517</guid>
      <dc:creator>lee_connor</dc:creator>
      <dc:date>2018-09-04T14:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense and SAML setup for Google auth - 500 error</title>
      <link>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-and-SAML-setup-for-Google-auth-500-error/m-p/91324#M1518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Turns out this was due to our SSL certificate not being about to encrypt &lt;SPAN style="color: #737373; font-family: Arial, Helvetica, sans-serif; font-size: 13px;"&gt;SHA-256, SHA-384 and SHA-512 XML signatures, as they require the &lt;/SPAN&gt;&lt;STRONG style="font-size: 13px; background: #ffffff; color: #737373; font-family: Arial, Helvetica, sans-serif;"&gt;Microsoft Enhanced RSA and AES Cryptographic Provider&lt;/STRONG&gt;&lt;SPAN style="color: #737373; font-family: Arial, Helvetica, sans-serif; font-size: 13px;"&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #737373; font-family: Arial, Helvetica, sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #737373; font-family: Arial, Helvetica, sans-serif; font-size: 13px;"&gt;More details about cryptographic service providers (CSPs) and their capabilities may be found at:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://msdn.microsoft.com/en-us/library/windows/desktop/bb931357(v=vs.85).aspx" style="color: #007fc0; font-size: 13px; background: #ffffff; font-family: Arial, Helvetica, sans-serif;" target="_blank" title="https://msdn.microsoft.com/en-us/library/windows/desktop/bb931357(v=vs.85).aspx"&gt;https://msdn.microsoft.com/en-us/library/windows/desktop/bb931357(v=vs.85).aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #737373; font-family: Arial, Helvetica, sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #737373; font-family: Arial, Helvetica, sans-serif; font-size: 13px;"&gt;I used OpenSSL to convert the current certificate (cert and pfx) on the server, follow the instructions on:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #737373; font-family: Arial, Helvetica, sans-serif; font-size: 13px;"&gt;&lt;A href="https://azuliadesigns.com/sha256-cryptographic-service-provider-types/" title="https://azuliadesigns.com/sha256-cryptographic-service-provider-types/"&gt;https://azuliadesigns.com/sha256-cryptographic-service-provider-types/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once the new cert was installed the issue was resolved. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #737373; font-family: Arial, Helvetica, sans-serif; font-size: 13px;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 15:15:35 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Qlik-Sense-and-SAML-setup-for-Google-auth-500-error/m-p/91324#M1518</guid>
      <dc:creator>lee_connor</dc:creator>
      <dc:date>2018-09-13T15:15:35Z</dc:date>
    </item>
  </channel>
</rss>

