Common SAML Assertion Errors and Resolutions Flashcards

1
Q

Assertion Expired

A

The timestamp on the assertion is too old.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Assertion Invalid

A

The assertion is malformed, possibly due to a missing <Subject> element.</Subject>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Audience Invalid

A

The <Audience> value doesn’t match the Entity ID specified during SSO configuration.</Audience>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Issuer Mismatched

A

The issuer in the configuration doesn’t match the issuer in the assertion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Signature Invalid

A

The uploaded certificate failed to validate the signature in the assertion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Configuration Error/Perm Disabled

A

Issues in SAML configuration, such as a corrupt certificate or disabled settings.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Recipient Mismatched

A

The recipient in the assertion does not match the recipient configured in Salesforce.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Replay Detected

A

Salesforce detected a duplicate assertion ID.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Signature Invalid

A

The certificate uploaded failed to validate the signature in the assertion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Subject Confirmation Error

A

The <Subject> specified in the assertion does not match the one configured in Salesforce.</Subject>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly