Expand my Community achievements bar.

Unable to SSO users via ADFS 3.0 using IWA

Avatar

Level 1

We are currently planning a migration from ADFS 2.0 to ADFS 3.0. We have tested all relying party trusts successfully with the exception of our AEM trust, which authenticates successfully when using forms based authentication in ADFS 3.0 (FBA) but fails when using Windows authenticated integration (IWA). In the 2.0 environment this authenticates successfully via both FBA and IWA.

AEM uses SP-initiated SSO from the URL https://author-informa-prod62.adobecqms.net/ and rather than resolving the request results in an infinite browsing loop when using IWA in 3.0. No issues in 2.0.

We are not sure whether this is simply due to AEM being incompatible with ADFS 3.0 or if there are other IWA settings in 3.0 we can/should amend to make this RPT work, even though all other RPTs are successfully authenticating via IWA.

I am happy to share screenshots of configuration settings etc but at this point am just asking if any other users have successfully integrated AEM into their ADFS 3.0 environment using IWA, and if there were any issues along the way?

3 Replies

Avatar

Level 10

I am not sure if AEM supports this - i am checking with some internal teams. 

Avatar

Level 1

smacdonald2008 wrote...

I am not sure if AEM supports this - i am checking with some internal teams. 

 

Hello, was there any news on your side regarding this? Many thanks!

Avatar

Level 10

IIRC IWA works only with IE & other browser does not support.  If it is IE please send the SamlAuthenticationHandler configuration snapshot along with har file[A].   I would recommend to get official support help by filling daycare ticket since sharing har or snapshot of your live system   in open communities might be not good idea.

[A]   https://confluence.atlassian.com/kb/generating-har-files-and-analysing-web-requests-720420612.html