<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ADFS SAML - SHA-256 renders &amp;quot;Internal Server Error&amp;quot;? in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/ADFS-SAML-SHA-256-renders-quot-Internal-Server-Error-quot/m-p/1126290#M6413</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just want to confirm, this was our resolution as well. I was in touch with Qlik Support and we agreed that the actual problem was the Cryptographic Service Provider that's issuing the private key in the certificate was wrong. In order to support SHA-256, it requires a specific one "Microsoft Enhanced RSA and AES Cryptographic Provider". If it is not, the client will try to downgrade to SHA-1 and surely it will fail because the proxy was configured to use SHA256. &lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The solution is to either re-issue the certificate, or convert it using the method in the article:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.componentspace.com/Forums/1578/SHA256-and-Converting-the-Cryptographic-Provider-Type" rel="nofollow" target="_blank"&gt;http://www.componentspace.com/Forums/1578/SHA256-and-Converting-the-Cryptographic-Provider-Type&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to change on the ADFS side as well to SHA-256.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 May 2017 17:36:04 GMT</pubDate>
    <dc:creator>ergustafsson</dc:creator>
    <dc:date>2017-05-31T17:36:04Z</dc:date>
    <item>
      <title>ADFS SAML - SHA-256 renders "Internal Server Error"?</title>
      <link>https://community.qlik.com/t5/Management-Governance/ADFS-SAML-SHA-256-renders-quot-Internal-Server-Error-quot/m-p/1126286#M6409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have successfully set up ADFS SAML SSO, with office365 login. The authentication works fine, going to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://URL/adfs/hub" rel="nofollow" target="_blank"&gt;http://URL/adfs/hub&lt;/A&gt;&lt;SPAN&gt; bounces the user to the login site and then back.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, SHA-1 is not supposed to be widely supported after the end of this year, see &lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;&lt;A href="https://www.tbs-certificates.co.uk/FAQ/en/sha256.html"&gt;https://www.tbs-certificates.co.uk/FAQ/en/sha256.html&lt;/A&gt;&lt;/SPAN&gt; .&lt;/P&gt;&lt;P&gt;When using SHA-256 it gives me an internal server error, immediately (not bouncing to login site). This single change among the settings renders an error.&lt;/P&gt;&lt;P&gt;Any ideas why?&lt;/P&gt;&lt;P&gt;Found in the C:\ProgramData\Qlik\Sense\Log\Proxy\System\QLIK-SENSE_Service_Proxy.txt file:&lt;/P&gt;&lt;P&gt;Command=Authenticate request;Result=-2147467259;ResultText=Error: The I/O operation has been aborted because of either a thread exit or an application request&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See attached for screenshots.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 May 2016 15:01:43 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/ADFS-SAML-SHA-256-renders-quot-Internal-Server-Error-quot/m-p/1126286#M6409</guid>
      <dc:creator>ergustafsson</dc:creator>
      <dc:date>2016-05-23T15:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: ADFS SAML - SHA-256 renders "Internal Server Error"?</title>
      <link>https://community.qlik.com/t5/Management-Governance/ADFS-SAML-SHA-256-renders-quot-Internal-Server-Error-quot/m-p/1126287#M6410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="internal server error.png" class="jive-image image-1" src="/legacyfs/online/125436_internal server error.png" style="height: 661px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are the settings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 May 2016 15:02:10 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/ADFS-SAML-SHA-256-renders-quot-Internal-Server-Error-quot/m-p/1126287#M6410</guid>
      <dc:creator>ergustafsson</dc:creator>
      <dc:date>2016-05-23T15:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: ADFS SAML - SHA-256 renders "Internal Server Error"?</title>
      <link>https://community.qlik.com/t5/Management-Governance/ADFS-SAML-SHA-256-renders-quot-Internal-Server-Error-quot/m-p/1126288#M6411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are troubleshooting a similar issue. Did you find a resolution for this? Please post your findings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our setup is similar to yours except, we use an internal corporate ID provider.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the logs (I believe, proxy audit log) shows an error "Unanticipated ComponentSpace.SAML2.Exceptions.SAMLSignatureException occurred for connection"!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Clearly, Qlik sense proxy throws an exception before reaching out the ID provider. The error seems to be from one of the dll used by the proxy service. I suspect if Qlik sense cannot read the encrypted signature from Idp meta data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would greatly appreciated!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2016 14:50:11 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/ADFS-SAML-SHA-256-renders-quot-Internal-Server-Error-quot/m-p/1126288#M6411</guid>
      <dc:creator />
      <dc:date>2016-07-27T14:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: ADFS SAML - SHA-256 renders "Internal Server Error"?</title>
      <link>https://community.qlik.com/t5/Management-Governance/ADFS-SAML-SHA-256-renders-quot-Internal-Server-Error-quot/m-p/1126289#M6412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We found a resolution for this issue! If someone is having a similar issue, try this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like the issue is with the certificate that you choose under 'Proxy / Security'. Though, the documentation says that the certificate chosen here is merely used for presenting it to the browser, it plays much bigger role than that. The private key and the associated Cryptographic Service Provider in the certificate should support SHA-256 XML signatures. If it doesn't the certificate has to be updated with a different provider. It's very simple running couple of ssl commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look at this link for detailed instructions: &lt;A href="http://www.componentspace.com/Forums/1578/SHA256-and-Converting-the-Cryptographic-Provider-Type" title="http://www.componentspace.com/Forums/1578/SHA256-and-Converting-the-Cryptographic-Provider-Type"&gt;SHA-256 and Converting the Cryptographic Service Provider Type&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2016 22:19:37 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/ADFS-SAML-SHA-256-renders-quot-Internal-Server-Error-quot/m-p/1126289#M6412</guid>
      <dc:creator />
      <dc:date>2016-08-10T22:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: ADFS SAML - SHA-256 renders "Internal Server Error"?</title>
      <link>https://community.qlik.com/t5/Management-Governance/ADFS-SAML-SHA-256-renders-quot-Internal-Server-Error-quot/m-p/1126290#M6413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just want to confirm, this was our resolution as well. I was in touch with Qlik Support and we agreed that the actual problem was the Cryptographic Service Provider that's issuing the private key in the certificate was wrong. In order to support SHA-256, it requires a specific one "Microsoft Enhanced RSA and AES Cryptographic Provider". If it is not, the client will try to downgrade to SHA-1 and surely it will fail because the proxy was configured to use SHA256. &lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The solution is to either re-issue the certificate, or convert it using the method in the article:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.componentspace.com/Forums/1578/SHA256-and-Converting-the-Cryptographic-Provider-Type" rel="nofollow" target="_blank"&gt;http://www.componentspace.com/Forums/1578/SHA256-and-Converting-the-Cryptographic-Provider-Type&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to change on the ADFS side as well to SHA-256.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 May 2017 17:36:04 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/ADFS-SAML-SHA-256-renders-quot-Internal-Server-Error-quot/m-p/1126290#M6413</guid>
      <dc:creator>ergustafsson</dc:creator>
      <dc:date>2017-05-31T17:36:04Z</dc:date>
    </item>
  </channel>
</rss>

