<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cloudpath | Error &amp;quot;Unable to authorize via SAML&amp;quot;, G-Suite Authentication fails in RUCKUS Self-Help</title>
    <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/Cloudpath-Error-quot-Unable-to-authorize-via-SAML-quot-G-Suite/m-p/69876#M253</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt; Users experiencing authentication failures when using SAML-based authentication, particularly with external services like G-Suite.&lt;/P&gt;&lt;P class="lia-align-center"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Orlando_Elias_0-1697485696305.png" style="width: 543px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9290iDE4B339E67966D55/image-dimensions/543x347/is-moderation-mode/true?v=v2" width="543" height="347" role="button" title="Orlando_Elias_0-1697485696305.png" alt="Orlando_Elias_0-1697485696305.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Root Cause:&lt;/STRONG&gt; The Security Assertion Markup Language (SAML) &lt;STRONG&gt;&lt;U&gt;relies on precise time synchronization&lt;/U&gt;&lt;/STRONG&gt; between the systems involved (identity provider, service provider, and user's device) to ensure the security of authentication transactions.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resolution:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Ensure Accurate Time Configuration:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Confirm that both the Cloudpath instance and the virtual server have accurate time configurations.&lt;/LI&gt;&lt;LI&gt;Point NTP configurations to a reliable NTP server, such as RUCKUS's public NTP server (ntp.ruckuswireless.com).&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Automatic Time Synchronization:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Set up automatic NTP synchronization to ensure consistent and accurate time across systems.&lt;/LI&gt;&lt;LI&gt;Regularly monitor NTP synchronization to detect and address any time drift issues promptly.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Follow &lt;A href="https://docs.commscope.com/bundle/cloudpath-512-samlguide/page/GUID-9865DF60-D1B8-40E3-8DC8-1A26829F7F80-homepage.html" target="_blank" rel="noopener"&gt;this guide&lt;/A&gt; for instructions on how to configure SAML services in RUCKUS Cloudpath.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How SAML Works:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Request Initiation:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User requests access to a service.&lt;/LI&gt;&lt;LI&gt;Service Provider (SP) redirects the user to the Identity Provider (IdP) for authentication.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Authentication:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;IdP authenticates the user by requesting credentials (e.g., username and password).&lt;/LI&gt;&lt;LI&gt;IdP generates a SAML assertion containing authentication information encrypted with the SP's public key and user details.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;SAML Assertion:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SAML assertion includes a timestamp to ensure its freshness.&lt;/LI&gt;&lt;LI&gt;If the SAML assertion is too old (beyond a defined time window), the assertion is considered invalid.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Response to Service Provider:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;IdP sends the SAML assertion back to the user's browser.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Access Granted:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User's browser submits the SAML assertion to the SP.&lt;/LI&gt;&lt;LI&gt;SP validates the assertion's authenticity and, if valid, grants access.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2023 19:49:30 GMT</pubDate>
    <dc:creator>Orlando_Elias</dc:creator>
    <dc:date>2023-10-16T19:49:30Z</dc:date>
    <item>
      <title>Cloudpath | Error "Unable to authorize via SAML", G-Suite Authentication fails</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/Cloudpath-Error-quot-Unable-to-authorize-via-SAML-quot-G-Suite/m-p/69876#M253</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt; Users experiencing authentication failures when using SAML-based authentication, particularly with external services like G-Suite.&lt;/P&gt;&lt;P class="lia-align-center"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Orlando_Elias_0-1697485696305.png" style="width: 543px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/9290iDE4B339E67966D55/image-dimensions/543x347/is-moderation-mode/true?v=v2" width="543" height="347" role="button" title="Orlando_Elias_0-1697485696305.png" alt="Orlando_Elias_0-1697485696305.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Root Cause:&lt;/STRONG&gt; The Security Assertion Markup Language (SAML) &lt;STRONG&gt;&lt;U&gt;relies on precise time synchronization&lt;/U&gt;&lt;/STRONG&gt; between the systems involved (identity provider, service provider, and user's device) to ensure the security of authentication transactions.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Resolution:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Ensure Accurate Time Configuration:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Confirm that both the Cloudpath instance and the virtual server have accurate time configurations.&lt;/LI&gt;&lt;LI&gt;Point NTP configurations to a reliable NTP server, such as RUCKUS's public NTP server (ntp.ruckuswireless.com).&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Automatic Time Synchronization:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Set up automatic NTP synchronization to ensure consistent and accurate time across systems.&lt;/LI&gt;&lt;LI&gt;Regularly monitor NTP synchronization to detect and address any time drift issues promptly.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Follow &lt;A href="https://docs.commscope.com/bundle/cloudpath-512-samlguide/page/GUID-9865DF60-D1B8-40E3-8DC8-1A26829F7F80-homepage.html" target="_blank" rel="noopener"&gt;this guide&lt;/A&gt; for instructions on how to configure SAML services in RUCKUS Cloudpath.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How SAML Works:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Request Initiation:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User requests access to a service.&lt;/LI&gt;&lt;LI&gt;Service Provider (SP) redirects the user to the Identity Provider (IdP) for authentication.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Authentication:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;IdP authenticates the user by requesting credentials (e.g., username and password).&lt;/LI&gt;&lt;LI&gt;IdP generates a SAML assertion containing authentication information encrypted with the SP's public key and user details.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;SAML Assertion:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SAML assertion includes a timestamp to ensure its freshness.&lt;/LI&gt;&lt;LI&gt;If the SAML assertion is too old (beyond a defined time window), the assertion is considered invalid.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Response to Service Provider:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;IdP sends the SAML assertion back to the user's browser.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Access Granted:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User's browser submits the SAML assertion to the SP.&lt;/LI&gt;&lt;LI&gt;SP validates the assertion's authenticity and, if valid, grants access.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 19:49:30 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/Cloudpath-Error-quot-Unable-to-authorize-via-SAML-quot-G-Suite/m-p/69876#M253</guid>
      <dc:creator>Orlando_Elias</dc:creator>
      <dc:date>2023-10-16T19:49:30Z</dc:date>
    </item>
  </channel>
</rss>

