How to fix Gitlab Sign-in using Saml auth failed?

Viewed 207

I'm trying to configurate instance-wide SAML for self-managed GitLab instance with Gsuite. From my gsuite saml app i have SSO URL, Entity ID, Certificate, SHA-256 fingerprint. With this fingerprint calculator i convertet my sha256 fingerptint to sha1.

### OmniAuth Settings
 gitlab_rails['omniauth_enabled'] = true
 gitlab_rails['omniauth_allow_single_sign_on'] = ['saml']
 gitlab_rails['omniauth_sync_email_from_provider'] = 'saml'
 gitlab_rails['omniauth_sync_profile_from_provider'] = ['saml']
 gitlab_rails['omniauth_block_auto_created_users'] = false
 gitlab_rails['omniauth_auto_link_saml_user'] = true
 gitlab_rails['omniauth_auto_link_user'] = ['saml']
 gitlab_rails['omniauth_external_providers'] = ['saml', 'google_oauth2']
 gitlab_rails['omniauth_providers'] = [
   {
     name: 'saml',
     args: {
                assertion_consumer_service_url: 'https://my.gitlab.com/users/auth/saml/callback',
                idp_cert_fingerprint: '66:16:1F:00:........',
                idp_sso_target_url: 'https://my.gitlab.com/o/saml2/idp?idpid=...',
                issuer: 'https://my.gitlab.com/',
                name_identifier_format: 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent',
                attribute_statements: { email: ['email'] },
                certificate: '-----BEGIN CERTIFICATE-----<cert>-----END CERTIFICATE-----'          
           },
     labels: 'Provider name'
   }
 ]

In the browser, after I click to log in through the saml, and select a mail account, I get the following result. Tell me please what could be the reason? enter image description here

0 Answers
Related