You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用djangosaml2集成Django与Okta SAML遇实体ID缺失错误

问题:djangosaml2集成Okta时出现"Missing entity_id specification"错误

配置信息

当前settings.py中的SAML配置:

import os
BASEDIR = os.path.dirname(os.path.abspath(__file__))

SAML_CONFIG = {
    "strict": True,
    "debug": True   ,
    "service" :{
    "sp": {

    'name': 'XXX',
     'allow_unsolicited': True,
     'want_assertions_signed': True,  # assertion signing (default=True)
     'want_response_signed': True,
     "want_assertions_or_response_signed": True,  # is response signing required
     'name_id_format': "urn:oasis:names:tc:SAML:1.1:nameid-format:basic",


        "entityId": "https://localhost:8002/metadata/",
        "assertionConsumerService": {
            "url": "https://localhost:8002/?acs",
            "binding": "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
        },
        "singleLogoutService": {
            "url": "https://localhost:8002/?sls",
            "binding": "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
        },
        "NameIDFormat": "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress",
        "x509cert": "",
        "privateKey": ""
    },
    "idp": {
        # "entityId": "https://dev-92033760.okta.com/app/exv13qURtCj35d7/sso/saml/metadata",
        "entityId": "http://www.okta.com/3qURtCj35d7",
        "singleSignOnService": {
            "url": "https://dev-9203760.okta.com/app/dev-92033760_saml4july_1/exRtCj35d7/sso/saml",
            "binding": "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
        },
        "singleLogoutService": {
            "url": "https://dev-9233760.okta.com/app/dev-92033760_saml4july_1/exka35d7/sso/saml",
            "binding": "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
        },

    },
    },

    'metadata': {
      'local': [os.path.join(BASEDIR, 'remote_metadata.xml')],
      }

}

错误现象

从Okta重定向回应用后显示:

Authentication Error.
Access Denied.

日志抛出异常:

Traceback (most recent call last):
File "/home/zec/label-studio-project/djangosaml2/djangosaml2_venv/lib/python3.8/site-packages/djangosaml2/views.py", line 469, in post
response = client.parse_authn_request_response(
File "/home/zec/label-studio-project/djangosaml2/djangosaml2_venv/lib/python3.8/site-packages/saml2/client_base.py", line 773, in parse_authn_request_response
raise SAMLError("Missing entity_id specification")
saml2.SAMLError: Missing entity_id specification
Forbidden: /saml2/acs/

排查与解决

这个错误的核心原因是SP无法匹配到SAML响应中的IDP entity_id,或者配置存在冲突/错误,以下是针对性修复步骤:

1. 移除手动IDP配置,依赖元数据文件

你已经通过metadata.local加载了Okta的元数据文件,同时又手动配置了service.idp块,这会导致配置冲突,SP无法确定使用哪组IDP信息。删除service下的整个idp配置块,让SP完全从元数据文件读取IDP的entityID、SSO/SLO地址等信息,保证配置一致性。

2. 修正SP的EntityID和ACS/SLO地址

djangosaml2默认的端点路径是/saml2/acs/(ACS)、/saml2/sls/(SLO)、/saml2/metadata/(元数据),你当前配置的路径不符合框架默认规则,会导致响应解析失败。修正这几个地址:

  • entityId改为https://localhost:8002/saml2/metadata/
  • assertionConsumerService.url改为https://localhost:8002/saml2/acs/
  • singleLogoutService.url改为https://localhost:8002/saml2/sls/

3. 确保Okta应用配置与SP一致

  • 在Okta应用的SAML配置中,将Single sign-on URL设置为上述修正后的ACS地址https://localhost:8002/saml2/acs/
  • 将**Audience URI (SP Entity ID)**设置为SP的entityId值https://localhost:8002/saml2/metadata/
  • 确认Okta下载的remote_metadata.xml文件完整,包含正确的IDP entityID、证书、服务地址,无格式错误。

修正后的SAML_CONFIG示例

import os
BASEDIR = os.path.dirname(os.path.abspath(__file__))

SAML_CONFIG = {
    "strict": True,
    "debug": True,
    "service": {
        "sp": {
            'name': 'XXX',
            'allow_unsolicited': True,
            'want_assertions_signed': True,
            'want_response_signed': True,
            "want_assertions_or_response_signed": True,
            'name_id_format': "urn:oasis:names:tc:SAML:1.1:nameid-format:basic",
            "entityId": "https://localhost:8002/saml2/metadata/",
            "assertionConsumerService": {
                "url": "https://localhost:8002/saml2/acs/",
                "binding": "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
            },
            "singleLogoutService": {
                "url": "https://localhost:8002/saml2/sls/",
                "binding": "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
            },
            "NameIDFormat": "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress",
            "x509cert": "",
            "privateKey": ""
        }
    },
    'metadata': {
        'local': [os.path.join(BASEDIR, 'remote_metadata.xml')],
    }
}

最后验证

  • 重启Django应用
  • 清空浏览器缓存后重新发起登录请求
  • 检查Okta和SP的所有配置路径、entityID完全一致,无拼写或端口错误

内容的提问来源于stack exchange,提问作者tridenT

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 06:32:02