Error Message
When attempting to log in to ArcGIS Enterprise with Security Assertion Markup Language (SAML), the following error is returned:
Error:
Unable to login using Idp. IDP supports Encrypted SAML Assertion, but sends unencrypted Assertion
Cause
- The Encrypt Assertion option is enabled in Portal for ArcGIS.
- The samlcert certificate is not imported into the identity provider (IDP) portal.
Solution or Workaround
Disable the Encrypt Assertion option
- Log in to Portal for ArcGIS and click Organization > Settings > Security.
- In the Logins section, select the IDP.
- On the Specify properties page, expand Show advanced settings.
- Disable the Encrypt Assertion option.
- Click Save.
Import the samlcert certificate into the IDP portal
Note:
The following workaround may require the assistance of the organization's IT team.
- Disable the Encrypt Assertion option.
- Log in to Portal for ArcGIS and click Organization > Settings > Security.
- In the Logins section, select the identity provider.
- On the Specify properties page, expand Show advanced settings.
- Disable the Encrypt Assertion option.
- Click Save.
- Export the samlcert certificate.
- Log in to the ArcGIS Portal Administrator Directory.
- Click Security > SSLCertificates.
- Click the existing samlcert certificate.
- Click Export.
- Import the samlcert certificate into the IDP portal and find the token encryption settings.
- Activate the samlcert certificate once it is imported.
- Enable the Encrypt Assertion option.
- Log in to Portal for ArcGIS and click Organization > Settings > Security.
- In the Logins section, select the IDP.
- On the Specify properties page, expand Show advanced settings.
- Enable the Encrypt Assertion option.
- Click Save.
- Clear the browser cache and log back in using the SAML login.