Error: 'User Authentication Failed, Reason: Invalid SAML Assertion (13)'
Cisco Webex Meetings Site Administrators only
Error: 'User Authentication Failed, Reason: Invalid SAML Assertion (13)'
Reason: Invalid SAML Assertion (13)
Cause:
If you are receiving the following error:
This may be caused for the following reasons:
- The AuthnContextClassRef value may be missing from the SAML assertion being passed to Webex.
- The AuthnContextClassRef value in the SAML assertion doesn't match what is entered in the SSO Configuration page.
- Your company may be using an ADFS proxy for external users to login with. This causes the SAML assertion to have two different AuthnContextClassRef values depending on where the end user is logging in from (External vs Internal).
Solution:
To troubleshoot the issue:
- In your SAML assertion code, verify the AuthnContextClassRef value is present.
- Verify the AuthnContextClassRef value in the Cisco Webex Meetings Site Administration matches what is entered in the Webex SSO configuration page.
To check the settings:
- Log in to your Cisco Webex Meetings Site Administration page. (Example: https://SITENAME.webex.com/admin.php)
- Click Configuration in the left panel.
- Click Common Site Settings > SSO Configuration.
- In the Federated Web SSO Configuration section, verify the value in the AuthnContextClassRef: field matches what is entered in the SAML assertion.
- Log in to your Cisco Webex Meetings Site Administration page.
- Click Configuration in the left panel.
- Click Common Site Settings > SSO Configuration.
- Change the AuthnContextClassRef: field value to: urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport;urn:oasis:names:tc:SAML:2.0:ac:classes:Password;urn:federation:authentication:windows;urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified
If the issue persists after performing the steps in this article, contact the Webex technical support. For help, see: WBX162 - How Do I Contact Webex Customer Services or Technical Support?
Was this article helpful?