You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PingFederate作为SAML IDP对接AWS Cognito故障排查求助

求助:AWS Cognito配置SAML IDP时的错误排查及测试环境建议

我目前在把多租户应用的SSO从PingFederate迁移到AWS Cognito的过程中遇到了问题,想请各位帮忙排查,或者给我一些测试用SAML IDP的配置建议。

背景情况

我们的应用之前一直用PingFederate实现单点登录,现在计划切换到AWS Cognito。我已经完成了基础代码改造,应用现在可以调用Cognito完成认证并获取令牌,但最后一步配置用户池支持SAML IDP的时候卡住了。

之前测试PingFederate的时候,我把它的测试服务器同时配置成了IDP和SP——这样应用发起IDP请求后,PingFederate的IDP服务响应,接着触发SP处理流程,最终能正常回到应用。现在我想给Cognito搭建类似的测试环境,但在整合PingFederate和Cognito时,创建身份提供商时收到了如下错误:

We were unable to create identity provider: No SingleSignOn Http redirect binding location found in metadata. (Service: AWSCognitoIdentityProviderService; Status Code: 400; Error Code: InvalidParameterException; Request ID: 8f48b246-6513-11e8-a8a0-8177ff216d8a)

下面是我上传的SAML元数据文件内容:

<md:EntityDescriptor entityID="OTIDPQA" cacheDuration="PT1440M" ID="WRHOcPiQSytSdX73eJiSqU7NYk7" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"> 
  <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> 
    <md:KeyDescriptor use="signing"> 
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> 
        <ds:X509Data> 
          <ds:X509Certificate> encrypted certificate data </ds:X509Certificate> 
        </ds:X509Data> 
      </ds:KeyInfo> 
    </md:KeyDescriptor> 
    <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid- format:unspecified</md:NameIDFormat> 
    <md:SingleSignOnService Location="https://xxxxx-userpool-test.auth.us-east-2.amazoncognito.com/saml2/idpresponse" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"/> 
    <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="MiddleName" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> 
    <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="Email" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> 
    <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="generic1" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> 
    <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="subject" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> 
    <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="userId" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> 
    <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="restricted" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> 
    <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="FirstName" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> 
    <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="Role" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> 
    <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="UserName" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> 
    <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="LastName" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> 
  </md:IDPSSODescriptor> 
  <md:ContactPerson contactType="administrative"> 
    <md:Company>company data </md:Company> 
    <md:GivenName>first name data</md:GivenName> 
    <md:SurName>last name data</md:SurName> 
    <md:EmailAddress>email data</md:EmailAddress> 
    <md:TelephoneNumber>phone data</md:TelephoneNumber> 
  </md:ContactPerson> 
</md:EntityDescriptor>

问题根源分析

这个错误其实很明确:AWS Cognito要求SAML IDP的元数据必须包含HTTP Redirect绑定的SingleSignOnService端点,但你现在的元数据里只有一个HTTP-POST绑定的条目,而且这个条目的Location还配置错了——它指向的是Cognito作为SP接收IDP响应的/saml2/idpresponse地址,而不是PingFederate作为IDP的SSO发起地址。

修复步骤

  1. 修正SingleSignOnService配置
    你需要从PingFederate控制台导出正确的IDP元数据,或者手动修改现有元数据:

    • 添加一个HTTP-Redirect绑定的SSO服务条目
    • 把两个绑定的Location都改成PingFederate IDP的真实SSO跳转地址(比如https://your-pingfederate-domain/idp/startSSO.ping?PartnerSpId=YOUR_COGNITO_SP_ENTITY_ID)
      示例修改后的代码:
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://your-pingfederate-server/idp/startSSO.ping?PartnerSpId=https://xxxxx-userpool-test.auth.us-east-2.amazoncognito.com"/>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://your-pingfederate-server/idp/startSSO.ping?PartnerSpId=https://xxxxx-userpool-test.auth.us-east-2.amazoncognito.com"/>
    

    注:YOUR_COGNITO_SP_ENTITY_ID就是你的Cognito用户池的实体ID,通常是用户池的域名URL。

  2. 验证元数据完整性
    检查元数据里的证书是否有效、NameIDFormat是否符合Cognito要求,以及属性声明是否和你后续要在Cognito里配置的属性映射对应。

  3. 测试环境替代方案
    如果暂时不想折腾PingFederate,推荐几个免费易用的SAML IDP测试工具:

    • Okta Developer Edition:免费开发者账号,图形化界面配置SAML IDP,上手快,适合快速验证Cognito的SAML流程。
    • OneLogin Developer Plan:同样提供免费的开发环境,支持一键生成SAML元数据,和Cognito整合很顺畅。
    • SimpleSAMLphp:开源SAML解决方案,可以自己部署本地IDP,适合需要自定义测试场景的情况。

额外配置提示

当你上传修正后的元数据到Cognito后,记得:

  • 在Cognito用户池的IDP配置里,将PingFederate返回的SAML属性(比如Email、UserName)映射到Cognito的用户属性
  • 测试时可以直接访问Cognito的托管登录页面,验证是否能正常跳转到PingFederate的登录界面,完成认证后回到应用。

内容的提问来源于stack exchange,提问作者Robin Trei

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 09:03:41