IdP Partner Configured With Message Level Encryption Causing 404 Error On Oracle Access Manager 11g R2PS3 (OAM 184.108.40.206) Federation Configured As SP
(Doc ID 2595431.1)
Last updated on NOVEMBER 21, 2019
Applies to:Oracle Access Manager - Version 220.127.116.11.190209 and later
Information in this document applies to any platform.
Oracle is not responsible for instructions/information from 3rd party sites that may be contained in this KM note.
Oracle Access Manager 11g R2PS3 (OAM 18.104.22.168) Federation configured as SP. OAM is proxied (OAM LB URL set to the DCC OHS host) by DCC OHS/WebGate. This OAM SP is integrated with a IdP Partner and this federation SSO was working fine until the IdP partner was configured for message level encryption. The SSO would error out with a HTTP 404 URL not found at the OAM DCC URL : "POST /oam/server/fed/sp/sso HTTP/1.1" 404.
Encryption method as outlined in this documentation.
Key transport Algorithm documentation.
This works in one environment, but when moving to the next environment the Federation ends up giving OAM page: /oam/server/fed/sp/sso HTTP 404
The OAM SP setup is configured per document, and has also matched the java.security file of the java (Java version "1.7.0_231" Java(TM) SE Runtime Environment (build 1.7.0_231-b08)) to see that it is configured to support this negotiation between the IdP and the SP partner.
However, between the working and the non-working setup, there was a missing kernel upgrade and upgrading the kernel from OEL 7.4 3.8.13-118.15.1.el7uek.x86_64 -> OEL 7.6 4.14.35-1844.2.5.el7uek.x86_64 resolved the issue.
There is no evidence that could be linked between the OAM DC proxied SP integration with the IdP had anything to do with this kernel upgrade.
This Note is to act as a recommendation that the system and the OAM services be always kept updated with all the patches released under "Recommended" tag to be on top of the BUG fixes for machine setups.
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document