SAML Authentication Error List

This page summarizes the errors that occur during SAML authentication.
Note: The remediation steps described here are intended for administrators.

Please check the cause and remediation steps for the relevant error code, then take action accordingly.

How to Check Error Details on the Error Screen

When an error occurs while running a SAML app, the following error screen is displayed.
Please check the error code by selecting "Show error details."
SAMLError01.png
 

List of Error Codes and Remediation Steps

Error Code

Cause

Remediation Steps

SAML-APP-ASSIGNMENT

The application has not been assigned to the target member

Please assign the relevant app to the target member.

SAML-INVALID-CONFIG

On the IdP (TrustLogin) side,
there is an issue with the SAML app configuration

Please check whether the SAML app configuration contains any errors.

Example: Expired certificate / Fingerprint mismatch / Incorrect signature settings

SAML-INVALID-REQUEST

The sign-in request is invalid or incomplete,
or the URL cannot be recognized

To determine whether this is a temporary issue,
please try signing in again.

If the issue persists, please check the following:
- URL / app configuration

SAML-CLOCK-SKEW

The clock on the SP (application) side is ahead,
causing the request timestamp to be in the future

Please check and correct the time synchronization (NTP settings)
on the SP-side server.

SAML-SESSION-EXPIRED

The sign-in request has expired
(5 minutes)

Please instruct the user to
sign in again from My Page.

SAML-DECODE-FAILED

The SAML request
cannot be decoded because it is empty, corrupted, or incorrectly encoded
(the sign-in request is corrupted and its contents cannot be read)

To determine whether this is a temporary issue,
please try signing in again.

If the issue persists, please check whether the request was generated correctly or has been tampered with on the SP side.
- Have the SP-side or IdP-side settings been changed recently?
- Do the SP-side encryption/signature settings differ from those on the IdP side?
- Does this occur for all users, or only a specific user? (If only for a specific user, the cause may be that user’s browser extensions, cache, etc.)

SAML-ACS-URL-MISMATCH

The ACS URL in the request
(Assertion Consumer Service URL) does not match the registered URL

Please have the administrator check whether the SP’s ACS URL
is correctly registered in the SAML app configuration.

SAML-INVALID-SIGNATURE

No signature is present, or signature verification failed

Please check and update whether the registered SP certificate
matches the certificate used to sign the request.

SAML-UNKNOWN

An unexpected error that does not fall into any known category

To determine whether this is a temporary issue,
please try signing in again.

If the issue persists, please contact support with details of your configuration.

 

If the Issue Is Not Resolved

If the issue is not resolved by the above, please contact us with the following information.
Note: If you would like to send files such as screenshots, please contact us at "support-jp@globalsign.com".

  • Error code (SAML-○○○)
  • Name of the relevant SAML app
  • The manual you referred to
  • When the issue occurred (e.g., whether it occurred right after initial setup, or whether something that was previously working suddenly stopped working)
  • Scope of the issue (all users / specific users)
  • Configuration details (e.g., a screenshot of the relevant SAML application settings)

Note: Please also review the items to check before contacting us, which are described here.

SAML Authentication Error List

This page summarizes the errors that occur during SAML authentication.
Note: The remediation steps described here are intended for administrators.

Please check the cause and remediation steps for the relevant error code, then take action accordingly.

How to Check Error Details on the Error Screen

When an error occurs while running a SAML app, the following error screen is displayed.
Please check the error code by selecting "Show error details."
SAMLError01.png
 

List of Error Codes and Remediation Steps

Error Code

Cause

Remediation Steps

SAML-APP-ASSIGNMENT

The application has not been assigned to the target member

Please assign the relevant app to the target member.

SAML-INVALID-CONFIG

On the IdP (TrustLogin) side,
there is an issue with the SAML app configuration

Please check whether the SAML app configuration contains any errors.

Example: Expired certificate / Fingerprint mismatch / Incorrect signature settings

SAML-INVALID-REQUEST

The sign-in request is invalid or incomplete,
or the URL cannot be recognized

To determine whether this is a temporary issue,
please try signing in again.

If the issue persists, please check the following:
- URL / app configuration

SAML-CLOCK-SKEW

The clock on the SP (application) side is ahead,
causing the request timestamp to be in the future

Please check and correct the time synchronization (NTP settings)
on the SP-side server.

SAML-SESSION-EXPIRED

The sign-in request has expired
(5 minutes)

Please instruct the user to
sign in again from My Page.

SAML-DECODE-FAILED

The SAML request
cannot be decoded because it is empty, corrupted, or incorrectly encoded
(the sign-in request is corrupted and its contents cannot be read)

To determine whether this is a temporary issue,
please try signing in again.

If the issue persists, please check whether the request was generated correctly or has been tampered with on the SP side.
- Have the SP-side or IdP-side settings been changed recently?
- Do the SP-side encryption/signature settings differ from those on the IdP side?
- Does this occur for all users, or only a specific user? (If only for a specific user, the cause may be that user’s browser extensions, cache, etc.)

SAML-ACS-URL-MISMATCH

The ACS URL in the request
(Assertion Consumer Service URL) does not match the registered URL

Please have the administrator check whether the SP’s ACS URL
is correctly registered in the SAML app configuration.

SAML-INVALID-SIGNATURE

No signature is present, or signature verification failed

Please check and update whether the registered SP certificate
matches the certificate used to sign the request.

SAML-UNKNOWN

An unexpected error that does not fall into any known category

To determine whether this is a temporary issue,
please try signing in again.

If the issue persists, please contact support with details of your configuration.

 

If the Issue Is Not Resolved

If the issue is not resolved by the above, please contact us with the following information.
Note: If you would like to send files such as screenshots, please contact us at "support-jp@globalsign.com".

  • Error code (SAML-○○○)
  • Name of the relevant SAML app
  • The manual you referred to
  • When the issue occurred (e.g., whether it occurred right after initial setup, or whether something that was previously working suddenly stopped working)
  • Scope of the issue (all users / specific users)
  • Configuration details (e.g., a screenshot of the relevant SAML application settings)

Note: Please also review the items to check before contacting us, which are described here.