Question

How to trace SAML Activity

Hi All,

Whenever I log in through SSO Login page, I am getting following error message in the browser.

"Your account has been disabled, contact your system administrator"

So, How to trace SAML activity?

Could you please provide inputs?

Regards,

AK

Comments

Keep up to date on this post and subscribe to comments

November 18, 2019 - 5:22am
Response to MarcLasserre_GCS

It is in Pega v8.3

Pega
November 19, 2019 - 1:36am

Hi,

 

Are you trying to create new operator or using an existing Pega operator to login ? From the error message, it looks the operator record has been disabled. Can you check if Operator record is not disabled on Pega ?

For debugging SSO login process, you can enable logging for below classes and see.

com.pega.pegarules.integration.engine.internal.util.PRSAMLv2Utils 
com.pega.pegarules.integration.engine.internal.sso.saml.SAMLResponseHandler 
com.pega.pegarules.integration.engine.internal.sso.saml.SAMLRequestHandler 
com.pega.pegarules.integration.engine.internal.sso.AbstractSSOHandler 
com.pega.pegarules.integration.engine.internal.sso.saml.SAMLv2ACSHandler

Thanks,

Santhosh

November 19, 2019 - 4:32am
Response to bagas

Hi Santosh,

I am trying to create a new operatorID. 
I have more than one node(8-10) in staging environment.

So if I enable logging in one node. How can I identify the exact node to check the log?

 

Pega
November 20, 2019 - 4:35am
Response to A___K

Is the new operator record created in the system ?

Pega
November 19, 2019 - 1:50am

Hi,

You can also add SAML tracer in Chrome browser and capture the request URLs. Please find the attached snippet for more details.

Thank you,

Abhishek

November 19, 2019 - 4:44am
Response to goela1

Hi Abhishek,

Thank you for the response. 

I have tried the SAML tracer but I am getting a success message in the tracer.
In the browser, I am getting the error message  
"Your account has been disabled, contact your system administrator"
 

Pega
December 2, 2019 - 9:38am

Hi,

You can either trace from the Admin studio and selecting the activity that you want to trace.

You can use SAML tracer and Fiddler tools to trace the SAML activity from the browser which you need to download based upon the browser you are using.

"Your account has been disabled, contact your system administrator"

The above error generally appears when you have logged the incorrect passwords for quite a number of times.