SAP Knowledge Base Article - Public

2487567 - Troubleshooting SAML assertions when configuring SAML SSO in SAP Analytics Cloud

Symptom

You are configuring SAML SSO in SAP Analytics Cloud. When you validate the account you get an error message, pop-up window or a screen with this message:

  • We've encountered an unexpected issue.
  • Please try again later or contact your system administrator if the problem persists.

Environment

  • SAP Analytics Cloud 2017
  • SAML IdP Provider of your choice

Resolution

Install a Chrome Extension

There are multiple tools and extensions that can help you read the SAML assertion. In this example, SAML Chrome panel is used.

Capture and display the SAML assertions by opening Chrome Developer Tools and select the new tab SAML after installing the extension.

1_Chrome_Plugin.png

Activate this extension in Incognito mode as well while validating the SAML configuration.

To do that go to: Chrome menu Extensions:

2_Incognito.png

What to capture

  1. When you are offered to validate your configuration, open your incognito Window.
  2. Open the Chrome Web development tools (F12 or Option + Command + I in MacOS).
  3. Paste the URL from the validate windows.
  4. You should get redirected from SAP Analytics Cloud to your SAML IdP
  5. Type your username / password, after you should be redirected back to SAP Analytics Cloud.

In the last entry for the SAML Plugin, search for the content NameID, similar to:

<Subject>
            <NameID>username</NameID>
            <SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><SubjectConfirmationData
                InResponseTo="Sca4e6250-4899-4885-9f8d-3b7ceb21ca59-YtIF1X5MFKLMDLYJ8J2Zfju1bZXoUQ9Zr8UDbXK.C4w"
                NotOnOrAfter="2017-06-09T21:08:20.858Z"
                Recipient="https://authn.hana.ondemand.com/saml2/sp/acs/a14f33c4c/axxxx"/></SubjectConfirmation>
</Subject>

Case Sensitivity

SAP Analytics Cloud is case sensitive. If your NameID returned by your SAML IdP is Rose (mixed case), it will fail as your User ID in SAC is ROSE (uppercase).
There is currently an enhancement created to be evaluated by development. This article will be updated when that enhancement is implemented.

  • USER IDs in SAP Analytics Cloud are all Uppercase while the SAML IdP may be passing the NameID in lowercase or mixed case.
  • E-mail is also case sensitive, you need to verify that your SAML IdP e-mail entries match uppercase and lowercase exactly with the entries in SAP Analytics Cloud.
  • For example, user@company.com will be rejected if the entry is User@example.com in SAC.

See Also

Your feedback is important to help us improve our knowledge base.
Please rate how useful you found this article by using the star rating feature at the beginning of this article.
Thank you.

Keywords

SAML, SSO, authentication, EPM-ODS, Cloud for Analytics, C4P, Cloud4Analytics, CloudforAnalytics, Cloud 4 Planning, HCP, C4A, BOC, SAPBusinessObjectsCloud, BusinessObjectsCloud, BOBJ, BOBJcloud, BOCloud., BICloud, SBOC, SAC , KBA , saml , adf , LOD-ANA , SAP Analytics Cloud , LOD-ANA-BI , SAP Analytics Cloud - Business Intelligence (BOC) , How To

Product

SAP Analytics Cloud 1.0