IBM Support

RelayState error message received for SAML authentication

Troubleshooting


Problem

When you attempt to log in to IBM Engineering Lifecycle Management (ELM) from a non-Jazz Home screen, you are not automatically redirected by Jazz Authorization Server (JAS) to your IdP for authentication. You are only redirected when you begin by accessing a secured resource within ELM. Instead, you might receive an error such as:

[ERROR] CWWKS5041E: The expected RelayState parameter was not included in the SAML response message from the IdP.

If you are unable to change the IdP settings to send the RelayState parameter (which might not be permitted), then there is a work-around to change two settings on WebSphere Application Server Liberty.

a. Set useRelayStateForTarget to false.
b. Set the targetPageUrl to the IdP-initiated SSO default landing page

For more information about these properties, see SAML Web SSO 2.0 Authentication.

Document Location

Worldwide


[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSPRJQ","label":"IBM Engineering Lifecycle Management Base"},"Component":"SAML;JAS","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.0.1 and higher","Edition":"","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

More support for:
IBM Engineering Lifecycle Management Base

Software version:
6.0.1 and higher

Document number:
6123579

Modified date:
28 April 2021

UID

ibm16123579

Manage My Notification Subscriptions