# SAML Single Sign On Help Needed.

**URL:** <https://forum.mautic.org/t/saml-single-sign-on-help-needed/8733>\
**Category:** Product Support\
**Created:** [June 14, 2017, 6:07am UTC](https://forum.mautic.org/t/saml-single-sign-on-help-needed/8733 "2017-06-14T06:07:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anoopsnm](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@anoopsnm](https://forum.mautic.org/u/anoopsnm)\
**Post date:** [June 14, 2017, 6:07am UTC](https://forum.mautic.org/t/saml-single-sign-on-help-needed/8733/1 "2017-06-14T06:07:30Z")

</div>

Hello,  
  
  
  
I have install mautic in the localhost. In the SAML SSO Settings page I have entered the relevant details and saved/applied changes. I got the metadata from the url [https://127.0.0.1/mautic/saml/metadata.xml](https://127.0.0.1/mautic/saml/metadata.xml) and configured it in my IDP that uses Shibboleth (IDP is also in my network). Now when I try to access the mautic page it gets rightly redirected to the IDP. But after logging in I am getting redirected to the login page of mautic again with the message “Assertions must be signed”.  
  
  
  
What should I be doing to fix this? Have I missed anything in the documentation?  
  
  
  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![anoopsnm](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@anoopsnm](https://forum.mautic.org/u/anoopsnm)\
**Post date:** [June 14, 2017, 6:07am UTC](https://forum.mautic.org/t/saml-single-sign-on-help-needed/8733/2 "2017-06-14T06:07:30Z")

</div>

Hello,

I have install mautic in the localhost. In the SAML SSO Settings page I have entered the relevant details and saved/applied changes. I got the metadata from the url [https://127.0.0.1/mautic/saml/metadata.xml](https://127.0.0.1/mautic/saml/metadata.xml) and configured it in my IDP that uses Shibboleth (IDP is also in my network). Now when I try to access the mautic page it gets rightly redirected to the IDP. But after logging in I am getting redirected to the login page of mautic again with the message “Assertions must be signed”.

What should I be doing to fix this? Have I missed anything in the documentation?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![hmmmonteiro](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/hmmmonteiro/32/12978_2.png) [@hmmmonteiro](https://forum.mautic.org/u/hmmmonteiro)\
**Post date:** [October 15, 2024, 12:55pm UTC](https://forum.mautic.org/t/saml-single-sign-on-help-needed/8733/3 "2024-10-15T12:55:50Z")

</div>

Old post, so I’ll just leave this here for future reference.

One must define a relaying party (relaying-party.xml) for the Mautic SP, such as:

```
<bean parent="RelyingPartyByName" c:relyingPartyIds="https://mautic.example.org">
	<property name="profileConfigurations">
	<list>
        <bean parent="SAML2.SSO" p:encryptAssertions="false" p:signAssertions="true" p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" />
	</list>
    </property>
</bean>

```
