# Trouble With SAML

**URL:** <https://forum.mautic.org/t/trouble-with-saml/8004>\
**Category:** Product Support\
**Created:** [March 23, 2017, 4:49pm UTC](https://forum.mautic.org/t/trouble-with-saml/8004 "2017-03-23T16:49:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![evanpyrz](https://avatars.discourse-cdn.com/v4/letter/e/c77e96/32.png) [@evanpyrz](https://forum.mautic.org/u/evanpyrz)\
**Post date:** [March 23, 2017, 4:49pm UTC](https://forum.mautic.org/t/trouble-with-saml/8004/1 "2017-03-23T16:49:43Z")

</div>

I am trying to configure Auth0’s SAML provider with a fresh Mautic installation. I was able to get them connected through to where I can access Mautic, it redirects me to the SAML provider, I login (successfully according to IDP logs) and then am redirected back to Mautic’s [http://my-domain.com/s/saml/login\_check](http://my-domain.com/s/saml/login_check).  
  
  
  
However, once I am redirected back after successfully being authenticated, I am taken to the regular Mautic login screen and given the message “Invalid login. Please verify credentials”. This seems to happen for both users that are already within Mautic’s internal user database, or for new users that are only authenticated through the external IDP.  
  
  
  
There are no messages in Mautic’s logs either.  
  
  
  
Any suggestions on where to look would be appreciated!  
  
  
  
Eric

---

<div class="post-metadata">

**Author:** ![evanpyrz](https://avatars.discourse-cdn.com/v4/letter/e/c77e96/32.png) [@evanpyrz](https://forum.mautic.org/u/evanpyrz)\
**Post date:** [March 23, 2017, 4:49pm UTC](https://forum.mautic.org/t/trouble-with-saml/8004/2 "2017-03-23T16:49:43Z")

</div>

I am trying to configure Auth0’s SAML provider with a fresh Mautic installation. I was able to get them connected through to where I can access Mautic, it redirects me to the SAML provider, I login (successfully according to IDP logs) and then am redirected back to Mautic’s [http://my-domain.com/s/saml/login\_check](http://my-domain.com/s/saml/login_check).

However, once I am redirected back after successfully being authenticated, I am taken to the regular Mautic login screen and given the message “Invalid login. Please verify credentials”. This seems to happen for both users that are already within Mautic’s internal user database, or for new users that are only authenticated through the external IDP.

There are no messages in Mautic’s logs either.

Any suggestions on where to look would be appreciated!

Eric

---

<div class="post-metadata">

**Author:** ![jimlawsonuvm](https://avatars.discourse-cdn.com/v4/letter/j/d07c76/32.png) [@jimlawsonuvm](https://forum.mautic.org/u/jimlawsonuvm)\
**Post date:** [April 5, 2017, 6:19pm UTC](https://forum.mautic.org/t/trouble-with-saml/8004/3 "2017-04-05T18:19:33Z")

</div>

Same problem here, except IDP in my case is Shibboleth 3.3.1. Would love to be able to turn up any debugging messages to try to see what’s going on. I think I’ve done the proper attribute mapping, but still “Invalid login. Please verify credentials.”

---

<div class="post-metadata">

**Author:** ![jimlawsonuvm](https://avatars.discourse-cdn.com/v4/letter/j/d07c76/32.png) [@jimlawsonuvm](https://forum.mautic.org/u/jimlawsonuvm)\
**Post date:** [April 5, 2017, 7:14pm UTC](https://forum.mautic.org/t/trouble-with-saml/8004/4 "2017-04-05T19:14:17Z")

</div>

Figured out how to turn on debug. (put ‘debug’ =\> 1 in app/config/local.php)

Now debugging logs appear in app/logs/prod-DATE.php

I can now see the assertion coming from the IDP, and it has a good signature according to lightSAML, but:

[2017-04-05 20:04:52] app.WARNING: Request state “\_a72e06d992c3bfe63ac3612dd8d4024ba7965c2258” does not exist {“profile\_id”:“sso\_sp\_receive\_response”,“own\_role”:“sp”,“action”:“LightSaml\Action\Profile\FlushRequestStatesAction”,“top\_context\_id”:“0000000060ec08af000000000693f461”} [] [2017-04-05 20:04:52] security.INFO: Authentication request failed. {“exception”:"[object] (Symfony\Component\Security\Core\Exception\BadCredentialsException(code: 0): User does not include required fields. at /users/j/t/jtl/mautic.jtl.w3.uvm.edu-root/app/bundles/UserBundle/Security/User/UserCreator.php:88)"} []

I wonder what are the required fields? Here are the relevant bits from settings/local.php:

‘saml\_idp\_own\_password’ =\> null, ‘saml\_idp\_email\_attribute’ =\> ‘mail’, ‘saml\_idp\_username\_attribute’ =\> null, ‘saml\_idp\_firstname\_attribute’ =\> ‘givenName’, ‘saml\_idp\_lastname\_attribute’ =\> ‘uvmEduSurname’, ‘saml\_idp\_default\_role’ =\> 1,

---

<div class="post-metadata">

**Author:** ![jimlawsonuvm](https://avatars.discourse-cdn.com/v4/letter/j/d07c76/32.png) [@jimlawsonuvm](https://forum.mautic.org/u/jimlawsonuvm)\
**Post date:** [April 5, 2017, 7:44pm UTC](https://forum.mautic.org/t/trouble-with-saml/8004/5 "2017-04-05T19:44:45Z")

</div>

Forgot to mention, this is mautic v2.7.1

Looking at UserCreator.php it’s not getting _any_ of the required fields … The code is trying to call $user-\>getUsername, or $user-\>getEmail, or one of the other required fields, but not getting a result.

Unfortunately I don’t have enough PHP/Symfony experience to take this much further right now. Any advice welcome.

---

<div class="post-metadata">

**Author:** ![anoopsnm](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@anoopsnm](https://forum.mautic.org/u/anoopsnm)\
**Post date:** [June 19, 2017, 5:45am UTC](https://forum.mautic.org/t/trouble-with-saml/8004/6 "2017-06-19T05:45:48Z")

</div>

I am having the same issue. I tried debuggging the code. But could’nt find the problem/solution yet.

Has anyone found a solution yet?

Thanks  
Anoop
