<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic /samlauthn 403 untrusted http origin header scheme is not allowed error in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2061531#M24804</link>
    <description>&lt;P&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;In february 2023 qlik sense enterprise version, saml don`t work. After authorization on idp, browser redirect to host/virtualproxy/samlauthn and 403 untrusted http origin header scheme is not allowed error in network console. In november 2022 same settings to vp and idp work well.&lt;BR /&gt;&lt;BR /&gt;Has anyone encountered such a problem?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Danilich_qlik_0-1681821182111.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/105156i89B696D313D9F43F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Danilich_qlik_0-1681821182111.png" alt="Danilich_qlik_0-1681821182111.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Apr 2023 12:33:26 GMT</pubDate>
    <dc:creator>Daniel11</dc:creator>
    <dc:date>2023-04-18T12:33:26Z</dc:date>
    <item>
      <title>/samlauthn 403 untrusted http origin header scheme is not allowed error</title>
      <link>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2061531#M24804</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;In february 2023 qlik sense enterprise version, saml don`t work. After authorization on idp, browser redirect to host/virtualproxy/samlauthn and 403 untrusted http origin header scheme is not allowed error in network console. In november 2022 same settings to vp and idp work well.&lt;BR /&gt;&lt;BR /&gt;Has anyone encountered such a problem?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Danilich_qlik_0-1681821182111.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/105156i89B696D313D9F43F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Danilich_qlik_0-1681821182111.png" alt="Danilich_qlik_0-1681821182111.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 12:33:26 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2061531#M24804</guid>
      <dc:creator>Daniel11</dc:creator>
      <dc:date>2023-04-18T12:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: /samlauthn 403 untrusted http origin header scheme is not allowed error</title>
      <link>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2061939#M24807</link>
      <description>&lt;P&gt;If you copy the Proxy folder from the November 2022 version and replace the February 2023 one with it, then everything works.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 09:40:49 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2061939#M24807</guid>
      <dc:creator>Daniel11</dc:creator>
      <dc:date>2023-04-19T09:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: /samlauthn 403 untrusted http origin header scheme is not allowed error</title>
      <link>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2085309#M25196</link>
      <description>&lt;P&gt;Hi, i am encountering the same issue here. Client is using ForgeRock OpenAM with SAML2.0. The May 2022 version had no issues at all, after upgrading to May 2023 it stopped working with this error.&amp;nbsp; So far we checked everything, and im seeing the following changes that can possible have effect on this.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE width="672px"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="90px"&gt;
&lt;P&gt;QB-14622&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="201px"&gt;
&lt;P&gt;Qlik Sense: Header injection redirects into non-existing subdomain&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="381px"&gt;
&lt;P&gt;The "Host allow list" in Virtual Proxy settings trusted all subdomains of the given entry. This has been fixed by adding an option for strict validation that only allows the given entry. The new proxy configuration setting "StrictValidateWhitelist" allows switching between the behaviors. The default is set to false (all subdomains trusted). If you need strict validation, enable the setting and restart the proxy.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="90px"&gt;
&lt;P&gt;QB-14363&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="201px"&gt;
&lt;P&gt;Qlik Sense: Unencrypted origin trusted by default&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="381px"&gt;
&lt;P&gt;Fixed a problem that allowed unencrypted HTTP origin header in Qlik Sense for HTTPS protocol requests.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;I don't think it is pefrerable to replace the proxy folder with an older version and get possible compatibility issues due to that.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 13:06:49 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2085309#M25196</guid>
      <dc:creator>nvankorlaar</dc:creator>
      <dc:date>2023-06-19T13:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: /samlauthn 403 untrusted http origin header scheme is not allowed error</title>
      <link>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2085599#M25205</link>
      <description>&lt;P&gt;Hi.&lt;BR /&gt;Thanks for the info.&lt;BR /&gt;QB-14363 - most likely caused the error&lt;BR /&gt;QB-14622 - does not help to solve the problem. I tried it on the February version earlier and just tried it on the May version with patch 1.&lt;/P&gt;
&lt;P&gt;Replacing the folder is only a debug of the problem, but not a solution to it, of course.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 07:19:56 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2085599#M25205</guid>
      <dc:creator>Daniel11</dc:creator>
      <dc:date>2023-06-20T07:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: /samlauthn 403 untrusted http origin header scheme is not allowed error</title>
      <link>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2086133#M25211</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;Thanks for posting.&lt;/P&gt;
&lt;P&gt;This seems related to a known defect -&amp;nbsp;QB-19046 that will be fixed in the incoming August 2023 release.&lt;/P&gt;
&lt;P&gt;The issue arises, if is indeed the same issue, when the Origin is "null".&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Albert&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 07:30:38 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2086133#M25211</guid>
      <dc:creator>Albert_Candelario</dc:creator>
      <dc:date>2023-06-21T07:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: /samlauthn 403 untrusted http origin header scheme is not allowed error</title>
      <link>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2424095#M26708</link>
      <description>&lt;P&gt;I have the same issue on august 2023 Patch 11. I still see the errror message.&lt;/P&gt;
&lt;HEADER class="errorcode"&gt;403&lt;/HEADER&gt;
&lt;P class="errormessage"&gt;Forbidden&lt;/P&gt;
&lt;P class="errormessage"&gt;Untrusted http origin header scheme is not allowed.&lt;/P&gt;
&lt;P class="errormessage"&gt;I'm able to login using NTLM, But sso is still not working&lt;/P&gt;
&lt;P class="errormessage"&gt;Any Suggestion.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 12:52:02 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2424095#M26708</guid>
      <dc:creator>atiwari</dc:creator>
      <dc:date>2024-02-27T12:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: /samlauthn 403 untrusted http origin header scheme is not allowed error</title>
      <link>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2464858#M27517</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/16958"&gt;@Albert_Candelario&lt;/a&gt;&amp;nbsp; I upgraded Qlik Sense to Feb 2024 Version and Still encounter the&amp;nbsp;403 Forbidden Untrusted http origin header scheme is not allowed.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LTIAT95_0-1719220487961.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/168366iB68ED11C8DE6C3E6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="LTIAT95_0-1719220487961.png" alt="LTIAT95_0-1719220487961.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Is it still a bug in Feb 2024 Version. Applied Feb 2024 patch 6 , still the same issue.&lt;/P&gt;
&lt;P class="errormessage"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 09:16:36 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2464858#M27517</guid>
      <dc:creator>atiwari</dc:creator>
      <dc:date>2024-06-24T09:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: /samlauthn 403 untrusted http origin header scheme is not allowed error</title>
      <link>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2466028#M27541</link>
      <description>&lt;P&gt;Okay, so After Troubleshooting I found the Issue is with HTTP communication. I found in feb 2024 SSO is not working if your IDP is having HTTP.&amp;nbsp; The same is working in August 2022 Version.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/16958"&gt;@Albert_Candelario&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/226519"&gt;@Daniel11&lt;/a&gt;&amp;nbsp; Is there any official announcement from Qlik to close the http communication in newer version?&lt;/P&gt;
&lt;P&gt;Any workaround how we can use the http in feb 2024 version.&lt;/P&gt;
&lt;P&gt;Note: I have http enabled in proxy.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 11:09:39 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/samlauthn-403-untrusted-http-origin-header-scheme-is-not-allowed/m-p/2466028#M27541</guid>
      <dc:creator>atiwari</dc:creator>
      <dc:date>2024-06-27T11:09:39Z</dc:date>
    </item>
  </channel>
</rss>

