Total Pageviews

Tuesday, August 3, 2021

Github and ADFS SAML integration error method="GitHub::Authentication::SAML.rails_authenticate" ip=yourip at="failure - Invalid SAML response" login=_unknown errors='["Digest mismatch", "No assertion found", "Audience is invalid. Audience attribute does not match

 ADFS and Github integration error

Error on github side

method="GitHub::Authentication::SAML.rails_authenticate" ip=yourip at="failure - Invalid SAML response" login=_unknown errors='["Digest mismatch", "No assertion found", "Audience is invalid. Audience attribute does not match


Solution:

The issue was Github Single Sing on URL and/or Issuer url was not correct, make sure to compare the value of IDP ACS and entityid with GitHub configuration.



github integration with ADFS using SAML "failure - Invalid SAML response" '["Digest mismatch"]'

 ADFS and Github SAML integration error

Error

"failure - Invalid SAML response" '["Digest mismatch"]'


Solution:

This error is a SAML integration error and it can occur during any application SAML integration. The real cause of this error is due to the Certificate miss-match. The issue was Github had a different certificate than the IDP certificate. make sure you download the correct certificate from the ADFS side or if you don't know which certificate, you can copy the certificate from the IDP file and upload the certificate (after decrypting) to the GitHub side. Also, make sure the IDP encryption is checked on the GitHub site and the certificate is showing correct values after uploading into GitHub.


other issues could be, the user does not exist on the GitHub side(user has to be present in Github users directory) or the right roles are not being passed.


Wednesday, June 16, 2021

GCP Network tiers selection

 Premium

hight cost.

Traffic leaves the GCP network closer to the destination. 

Less distance and hope

More secure and faster transportation.



 Standard


Lest expensive

Traffic leaves the Google network near the Source.

Most of the traffic stays on the public network.


Monday, June 14, 2021

KeyClock initial username and password

after unzipping the Keyclock folder go to the following url and enter the username and password. whatever you entered for the first time will be your admin username and password. 

 http://localhost:8080/auth



Wednesday, June 9, 2021

GCP Folders definition

Projects


1. Core components of GCP
2. GCP requires to use Projects.
3. Each resource only belongs to one Project.
4. Projects can be part of an Organization.
5. Projects are core IAM implementation point.
6. Projects provisioning is simple only one mandatory field is required and free of charge.
7. Projects can have different owners and users associated with and they can be managed and billed separately. 
8. Resources belongs to Projects they are be instances, cloud store boxes, services or API's.



GCP resource policy Most restricted vs least restricted


Most restricted policy always override least restricted policy in GCP at any level







GCP Organization Hierarchy