PingFederate作为SAML IDP对接AWS Cognito故障排查求助
我目前在把多租户应用的SSO从PingFederate迁移到AWS Cognito的过程中遇到了问题,想请各位帮忙排查,或者给我一些测试用SAML IDP的配置建议。
背景情况
我们的应用之前一直用PingFederate实现单点登录,现在计划切换到AWS Cognito。我已经完成了基础代码改造,应用现在可以调用Cognito完成认证并获取令牌,但最后一步配置用户池支持SAML IDP的时候卡住了。
之前测试PingFederate的时候,我把它的测试服务器同时配置成了IDP和SP——这样应用发起IDP请求后,PingFederate的IDP服务响应,接着触发SP处理流程,最终能正常回到应用。现在我想给Cognito搭建类似的测试环境,但在整合PingFederate和Cognito时,创建身份提供商时收到了如下错误:
We were unable to create identity provider: No SingleSignOn Http redirect binding location found in metadata. (Service: AWSCognitoIdentityProviderService; Status Code: 400; Error Code: InvalidParameterException; Request ID: 8f48b246-6513-11e8-a8a0-8177ff216d8a)
下面是我上传的SAML元数据文件内容:
<md:EntityDescriptor entityID="OTIDPQA" cacheDuration="PT1440M" ID="WRHOcPiQSytSdX73eJiSqU7NYk7" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate> encrypted certificate data </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid- format:unspecified</md:NameIDFormat> <md:SingleSignOnService Location="https://xxxxx-userpool-test.auth.us-east-2.amazoncognito.com/saml2/idpresponse" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"/> <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="MiddleName" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="Email" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="generic1" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="subject" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="userId" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="restricted" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="FirstName" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="Role" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="UserName" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname- format:basic" Name="LastName" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="administrative"> <md:Company>company data </md:Company> <md:GivenName>first name data</md:GivenName> <md:SurName>last name data</md:SurName> <md:EmailAddress>email data</md:EmailAddress> <md:TelephoneNumber>phone data</md:TelephoneNumber> </md:ContactPerson> </md:EntityDescriptor>
问题根源分析
这个错误其实很明确:AWS Cognito要求SAML IDP的元数据必须包含HTTP Redirect绑定的SingleSignOnService端点,但你现在的元数据里只有一个HTTP-POST绑定的条目,而且这个条目的Location还配置错了——它指向的是Cognito作为SP接收IDP响应的/saml2/idpresponse地址,而不是PingFederate作为IDP的SSO发起地址。
修复步骤
修正SingleSignOnService配置
你需要从PingFederate控制台导出正确的IDP元数据,或者手动修改现有元数据:- 添加一个
HTTP-Redirect绑定的SSO服务条目 - 把两个绑定的Location都改成PingFederate IDP的真实SSO跳转地址(比如
https://your-pingfederate-domain/idp/startSSO.ping?PartnerSpId=YOUR_COGNITO_SP_ENTITY_ID)
示例修改后的代码:
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://your-pingfederate-server/idp/startSSO.ping?PartnerSpId=https://xxxxx-userpool-test.auth.us-east-2.amazoncognito.com"/> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://your-pingfederate-server/idp/startSSO.ping?PartnerSpId=https://xxxxx-userpool-test.auth.us-east-2.amazoncognito.com"/>注:
YOUR_COGNITO_SP_ENTITY_ID就是你的Cognito用户池的实体ID,通常是用户池的域名URL。- 添加一个
验证元数据完整性
检查元数据里的证书是否有效、NameIDFormat是否符合Cognito要求,以及属性声明是否和你后续要在Cognito里配置的属性映射对应。测试环境替代方案
如果暂时不想折腾PingFederate,推荐几个免费易用的SAML IDP测试工具:- Okta Developer Edition:免费开发者账号,图形化界面配置SAML IDP,上手快,适合快速验证Cognito的SAML流程。
- OneLogin Developer Plan:同样提供免费的开发环境,支持一键生成SAML元数据,和Cognito整合很顺畅。
- SimpleSAMLphp:开源SAML解决方案,可以自己部署本地IDP,适合需要自定义测试场景的情况。
额外配置提示
当你上传修正后的元数据到Cognito后,记得:
- 在Cognito用户池的IDP配置里,将PingFederate返回的SAML属性(比如Email、UserName)映射到Cognito的用户属性
- 测试时可以直接访问Cognito的托管登录页面,验证是否能正常跳转到PingFederate的登录界面,完成认证后回到应用。
内容的提问来源于stack exchange,提问作者Robin Trei

