<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSO - Generic SAML Server - 504 Gateway Time-out in Portal</title>
    <link>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/240349#M426</link>
    <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;With regards to SSO integration using Generic SAML Server, I follow the &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Generic-SAML.htm?cshid=ID014" target="_blank" rel="noopener"&gt;guideline&amp;nbsp;&lt;/A&gt;and&amp;nbsp;&lt;/P&gt;&lt;H4&gt;Mandatory User Attributes &amp;amp; Claims&lt;/H4&gt;&lt;P&gt;Field Name Value&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;identity/claims/givenname&lt;/TD&gt;&lt;TD&gt;First Name&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;identity/claims/name&lt;/TD&gt;&lt;TD&gt;Last Name&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;identity/claims/emailaddress&lt;/TD&gt;&lt;TD&gt;Email Address&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;groups&lt;/TD&gt;&lt;TD&gt;Groups&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;urn:mace:dir:attribute-def:userId&lt;/TD&gt;&lt;TD&gt;User Id&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The IDP log in works. When user is redirected to &lt;A href="https://cloudinfra-gw.portal.checkpoint.com/api/saml/sso" target="_blank" rel="noopener"&gt;https://cloudinfra-gw.portal.checkpoint.com/api/saml/sso&lt;/A&gt;, it shows 504 Gateway Time-out.&amp;nbsp;My SAML assertion attributes are&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;saml:AttributeStatement&amp;gt;
	&amp;lt;saml:Attribute Name="UserID"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;67768004&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="username"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;ldo@securenvoy.com&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="email"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;ldo@securenvoy.com&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="groups"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;admin&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="urn:mace:dir:attribute-def:userId"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;67768004&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="identity/claims/givenname"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;Lan&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="identity/claims/name"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;Do&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="identity/claims/emailaddress"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;ldo@securenvoy.com&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
&amp;lt;/saml:AttributeStatement&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you help what could go wrong&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;BR /&gt;Lan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Feb 2025 11:28:57 GMT</pubDate>
    <dc:creator>donguyenthanhla</dc:creator>
    <dc:date>2025-02-04T11:28:57Z</dc:date>
    <item>
      <title>SSO - Generic SAML Server - 504 Gateway Time-out</title>
      <link>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/240349#M426</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;With regards to SSO integration using Generic SAML Server, I follow the &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Generic-SAML.htm?cshid=ID014" target="_blank" rel="noopener"&gt;guideline&amp;nbsp;&lt;/A&gt;and&amp;nbsp;&lt;/P&gt;&lt;H4&gt;Mandatory User Attributes &amp;amp; Claims&lt;/H4&gt;&lt;P&gt;Field Name Value&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;identity/claims/givenname&lt;/TD&gt;&lt;TD&gt;First Name&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;identity/claims/name&lt;/TD&gt;&lt;TD&gt;Last Name&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;identity/claims/emailaddress&lt;/TD&gt;&lt;TD&gt;Email Address&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;groups&lt;/TD&gt;&lt;TD&gt;Groups&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;urn:mace:dir:attribute-def:userId&lt;/TD&gt;&lt;TD&gt;User Id&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The IDP log in works. When user is redirected to &lt;A href="https://cloudinfra-gw.portal.checkpoint.com/api/saml/sso" target="_blank" rel="noopener"&gt;https://cloudinfra-gw.portal.checkpoint.com/api/saml/sso&lt;/A&gt;, it shows 504 Gateway Time-out.&amp;nbsp;My SAML assertion attributes are&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;saml:AttributeStatement&amp;gt;
	&amp;lt;saml:Attribute Name="UserID"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;67768004&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="username"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;ldo@securenvoy.com&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="email"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;ldo@securenvoy.com&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="groups"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;admin&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="urn:mace:dir:attribute-def:userId"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;67768004&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="identity/claims/givenname"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;Lan&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="identity/claims/name"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;Do&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
	&amp;lt;saml:Attribute Name="identity/claims/emailaddress"
					NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
					&amp;gt;
		&amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;ldo@securenvoy.com&amp;lt;/saml:AttributeValue&amp;gt;
	&amp;lt;/saml:Attribute&amp;gt;
&amp;lt;/saml:AttributeStatement&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you help what could go wrong&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;BR /&gt;Lan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 11:28:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/240349#M426</guid>
      <dc:creator>donguyenthanhla</dc:creator>
      <dc:date>2025-02-04T11:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSO - Generic SAML Server - 504 Gateway Time-out</title>
      <link>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/240708#M430</link>
      <description>&lt;P&gt;What happens when you run the "Test Connectivity" option under Identity Providers? &lt;/P&gt;
&lt;P&gt;I've found that running an additional browser extension such as SAML-Tracer (&lt;A href="https://chromewebstore.google.com/detail/saml-tracer/mpdajninpobndbfcldcmbpnnbhibjmch?hl=en&amp;amp;pli=1" target="_blank"&gt;https://chromewebstore.google.com/detail/saml-tracer/mpdajninpobndbfcldcmbpnnbhibjmch?hl=en&amp;amp;pli=1&lt;/A&gt;) to be helpful in tracking down request/response issues. &lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 18:14:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/240708#M430</guid>
      <dc:creator>masher</dc:creator>
      <dc:date>2025-02-07T18:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSO - Generic SAML Server - 504 Gateway Time-out</title>
      <link>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/240885#M443</link>
      <description>&lt;P&gt;Hi Masher&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use SAML tracer. Please find the steps&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Init test&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 830px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29580iB22B8B4CAC3968C6/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2. IDP log in with SAML request&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29581i9D879CD9E04169B5/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.jpg" alt="2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                    ID="_04c64b9513de19afe615"
                    Version="2.0"
                    IssueInstant="2025-02-11T02:43:18.159Z"
                    ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
                    Destination="https://securenvoy.azuredev.mysecurenvoy.com/identity/saml2?app=6134"
                    AssertionConsumerServiceURL="https://cloudinfra-gw.portal.checkpoint.com/api/saml/sso"
                    &amp;gt;
    &amp;lt;saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"&amp;gt;f1f35e8e-3aa5-4fd7-96a9-69259dba2c8d.cloudinfra.checkpoint.com&amp;lt;/saml:Issuer&amp;gt;
    &amp;lt;samlp:NameIDPolicy xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                        Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
                        AllowCreate="true"
                        /&amp;gt;
&amp;lt;/samlp:AuthnRequest&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Log in successfully. Redirect to&amp;nbsp;&lt;A href="https://cloudinfra-gw.portal.checkpoint.com/api/saml/sso" target="_blank" rel="noopener"&gt;https://cloudinfra-gw.portal.checkpoint.com/api/saml/sso&lt;/A&gt;. After a while, it show 504 Gateway timeout. The Test is still running&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29582iB1A4EFA197C7FA78/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.jpg" alt="3.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Detail SAML response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;Response xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
          xmlns:xsd="http://www.w3.org/2001/XMLSchema"
          xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
          xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
          xmlns="urn:oasis:names:tc:SAML:2.0:protocol"
          ID="_f0529997-2c88-44ab-8d1b-5dfc581aebf5"
          InResponseTo="_04c64b9513de19afe615"
          Version="2.0"
          IssueInstant="2025-02-11T02:47:06.8456102Z"
          Destination="https://cloudinfra-gw.portal.checkpoint.com/api/saml/sso"
          &amp;gt;
    &amp;lt;saml:Issuer&amp;gt;https://securenvoy.azuredev.mysecurenvoy.com/identity&amp;lt;/saml:Issuer&amp;gt;
    &amp;lt;Signature xmlns="http://www.w3.org/2000/09/xmldsig#"&amp;gt;
        &amp;lt;SignedInfo&amp;gt;
            &amp;lt;CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /&amp;gt;
            &amp;lt;SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" /&amp;gt;
            &amp;lt;Reference URI="#_f0529997-2c88-44ab-8d1b-5dfc581aebf5"&amp;gt;
                &amp;lt;Transforms&amp;gt;
                    &amp;lt;Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" /&amp;gt;
                    &amp;lt;Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /&amp;gt;
                &amp;lt;/Transforms&amp;gt;
                &amp;lt;DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" /&amp;gt;
                &amp;lt;DigestValue&amp;gt;AG8HAeeJwIugjxqzAx9pOHqqQp8kUgTwub3ssiaWo2o=&amp;lt;/DigestValue&amp;gt;
            &amp;lt;/Reference&amp;gt;
        &amp;lt;/SignedInfo&amp;gt;
        &amp;lt;SignatureValue&amp;gt;e+cg7CAbFqb375RMTrkn6Pu3e3VLvAwjHxHXfDlwjvT/qiwwL5aO3AS6SJf0wx71Vy7FhZoHoYsvr9J+BgSOrcmAJjWeAfkCyzQDI28Q1qj+16rnDO2BWt9SDyY0nnoGGRuhjTixZrgU3OwZ+XQTlbgSvmZSJ8RteTfSvPSr6T6VipAT7OtqWMgB8F5zBfwKV7rWkc5q3TAdGGu2Uyg/dhUI5ToVb/Bi6pc3h02jT/PEh/TxXFCEAPXhFiqYVmWjXgM9wOKmfsDm8I4WNcN3OUS3Eh5Sc4IcCtSfmYP+uLKH18yr4vhmgbBGRjbkRD7B6Qdk4ExltVusC+v4MSCVow==&amp;lt;/SignatureValue&amp;gt;
        &amp;lt;KeyInfo&amp;gt;
            &amp;lt;X509Data&amp;gt;
                &amp;lt;X509Certificate&amp;gt;MIIEMzCCAxugAwIBAgIUKncZWBUy7vm/+GNbBcsaT7OGaUkwDQYJKoZIhvcNAQELBQAwgagxCzAJBgNVBAYTAkdCMRIwEAYDVQQIDAlIYW1wc2hpcmUxFDASBgNVBAcMC0Jhc2luZ3N0b2tlMRMwEQYDVQQKDApTZWN1ckVudm95MRQwEgYDVQQLDAtFbmdpbmVlcmluZzEdMBsGA1UEAwwUc2VjdXJlbnZveS5kaXJlY3RvcnkxJTAjBgkqhkiG9w0BCQEWFnN5c3RlbXNAc2VjdXJlbnZveS5jb20wHhcNMjMwNTA5MDc1NDIyWhcNMjgwNTA4MDc1NDIyWjCBqDELMAkGA1UEBhMCR0IxEjAQBgNVBAgMCUhhbXBzaGlyZTEUMBIGA1UEBwwLQmFzaW5nc3Rva2UxEzARBgNVBAoMClNlY3VyRW52b3kxFDASBgNVBAsMC0VuZ2luZWVyaW5nMR0wGwYDVQQDDBRzZWN1cmVudm95LmRpcmVjdG9yeTElMCMGCSqGSIb3DQEJARYWc3lzdGVtc0BzZWN1cmVudm95LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALIyLdFrHvJEU5OgC8KqCqJ2+F5jwho+fusouu8DIBAx2L/ShhmekZqBbtHvwtLU73iHmHor3QZ7l1PzCAQnvBhUyg3nOmlxt2GwONtUlQ7+GYTWhVU1aF3fmKKuirxwK6l1kuAfvQi3BpeCh8pmKsmBIKyaaV5Rh3GdwqoUYq7lBFuPsL5XWWGhUNDjuSxl6EAPQ6a9HDG2CVKtALlNkZaLTE489eajXM+ifs2Ag/k8tqPv/LZrSbwjMsk1BJo/H9Bb3PxdDAkBK7c4KSear013sXj6QYPMi1o1nZAfA+F5JlPWnqd2VeQ76agQYzuMnh1jHI5ts6Ir2dgpB4R41K8CAwEAAaNTMFEwHQYDVR0OBBYEFLYWadrDG9Ghm8+xcYcdnujYy584MB8GA1UdIwQYMBaAFLYWadrDG9Ghm8+xcYcdnujYy584MA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAE1x1I0zgSDoZrd3Bc8r6RTStAsqAt4TARFHVlFcCY8MDy9kilMS5C57fWDtOeHgVeC4CsFc+cQuoensJ/NQTUFtze42bMwBjzloD+ZOt2plJspVJK/JBXZuSaKvn3cTQ8NhYeYJaGaxi/NhoAPjgZUItT9kSdiotVVpAXXR7QqgR6bX36qAW8QeASk4WZRCpMBjY5t8x34Iab8VzmJE38frjryYheglBs1zOYIMJNWIU+TDIjVjkBojAszCFikreELowGTkKq6uqtvYS24bHY0liIndZ7VKibfTqXdAjmswS/8uf9WJqvrkTmdFwj5OlZCeEIOOAwmCELrr2Bg2loI=&amp;lt;/X509Certificate&amp;gt;
            &amp;lt;/X509Data&amp;gt;
        &amp;lt;/KeyInfo&amp;gt;
    &amp;lt;/Signature&amp;gt;
    &amp;lt;Status&amp;gt;
        &amp;lt;StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" /&amp;gt;
    &amp;lt;/Status&amp;gt;
    &amp;lt;saml:Assertion Version="2.0"
                    ID="_41d43c47-b69c-4434-b3ca-3021232a3d09"
                    IssueInstant="2025-02-11T02:47:06.8460516Z"
                    &amp;gt;
        &amp;lt;saml:Issuer&amp;gt;https://securenvoy.azuredev.mysecurenvoy.com/identity&amp;lt;/saml:Issuer&amp;gt;
        &amp;lt;Signature xmlns="http://www.w3.org/2000/09/xmldsig#"&amp;gt;
            &amp;lt;SignedInfo&amp;gt;
                &amp;lt;CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /&amp;gt;
                &amp;lt;SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" /&amp;gt;
                &amp;lt;Reference URI="#_41d43c47-b69c-4434-b3ca-3021232a3d09"&amp;gt;
                    &amp;lt;Transforms&amp;gt;
                        &amp;lt;Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" /&amp;gt;
                        &amp;lt;Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /&amp;gt;
                    &amp;lt;/Transforms&amp;gt;
                    &amp;lt;DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" /&amp;gt;
                    &amp;lt;DigestValue&amp;gt;gDV6ZL8hUGrL56yGFVs6jgfKa/47ZiRsg2pZdMzhN9E=&amp;lt;/DigestValue&amp;gt;
                &amp;lt;/Reference&amp;gt;
            &amp;lt;/SignedInfo&amp;gt;
            &amp;lt;SignatureValue&amp;gt;ZtIRRMaVhUoQVM97/UjnIEHDWA71FLcQZoEnaNFaS5St0Cjx0midtTfiEIuFQtjjAUSMpw23xbBFolareRoFfZy/qn20KdynxBZXISw+OurBSiI9rYgKoenbAqpmACFcPoqc7SGlRAADL1GUV8CGzs/6PaYLzSO0UfPj8m61EUEeoymCoOgIV1KKfB+NIh3SRIn5+/a1FlxUZAuXh8OQ0RXGCvAUnwmB9A1iFKq8gvuJyxzFcXU4gPNNZzTJXQnCVAXHNjBUKBk0nwau6dlX69Hxg4j35Csmlsj33KJJi8UbZjKI+xTsCSmmKbJe1BfoVPPUISUjUFtZC6Eo+UGpGQ==&amp;lt;/SignatureValue&amp;gt;
            &amp;lt;KeyInfo&amp;gt;
                &amp;lt;X509Data&amp;gt;
                    &amp;lt;X509Certificate&amp;gt;MIIEMzCCAxugAwIBAgIUKncZWBUy7vm/+GNbBcsaT7OGaUkwDQYJKoZIhvcNAQELBQAwgagxCzAJBgNVBAYTAkdCMRIwEAYDVQQIDAlIYW1wc2hpcmUxFDASBgNVBAcMC0Jhc2luZ3N0b2tlMRMwEQYDVQQKDApTZWN1ckVudm95MRQwEgYDVQQLDAtFbmdpbmVlcmluZzEdMBsGA1UEAwwUc2VjdXJlbnZveS5kaXJlY3RvcnkxJTAjBgkqhkiG9w0BCQEWFnN5c3RlbXNAc2VjdXJlbnZveS5jb20wHhcNMjMwNTA5MDc1NDIyWhcNMjgwNTA4MDc1NDIyWjCBqDELMAkGA1UEBhMCR0IxEjAQBgNVBAgMCUhhbXBzaGlyZTEUMBIGA1UEBwwLQmFzaW5nc3Rva2UxEzARBgNVBAoMClNlY3VyRW52b3kxFDASBgNVBAsMC0VuZ2luZWVyaW5nMR0wGwYDVQQDDBRzZWN1cmVudm95LmRpcmVjdG9yeTElMCMGCSqGSIb3DQEJARYWc3lzdGVtc0BzZWN1cmVudm95LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALIyLdFrHvJEU5OgC8KqCqJ2+F5jwho+fusouu8DIBAx2L/ShhmekZqBbtHvwtLU73iHmHor3QZ7l1PzCAQnvBhUyg3nOmlxt2GwONtUlQ7+GYTWhVU1aF3fmKKuirxwK6l1kuAfvQi3BpeCh8pmKsmBIKyaaV5Rh3GdwqoUYq7lBFuPsL5XWWGhUNDjuSxl6EAPQ6a9HDG2CVKtALlNkZaLTE489eajXM+ifs2Ag/k8tqPv/LZrSbwjMsk1BJo/H9Bb3PxdDAkBK7c4KSear013sXj6QYPMi1o1nZAfA+F5JlPWnqd2VeQ76agQYzuMnh1jHI5ts6Ir2dgpB4R41K8CAwEAAaNTMFEwHQYDVR0OBBYEFLYWadrDG9Ghm8+xcYcdnujYy584MB8GA1UdIwQYMBaAFLYWadrDG9Ghm8+xcYcdnujYy584MA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAE1x1I0zgSDoZrd3Bc8r6RTStAsqAt4TARFHVlFcCY8MDy9kilMS5C57fWDtOeHgVeC4CsFc+cQuoensJ/NQTUFtze42bMwBjzloD+ZOt2plJspVJK/JBXZuSaKvn3cTQ8NhYeYJaGaxi/NhoAPjgZUItT9kSdiotVVpAXXR7QqgR6bX36qAW8QeASk4WZRCpMBjY5t8x34Iab8VzmJE38frjryYheglBs1zOYIMJNWIU+TDIjVjkBojAszCFikreELowGTkKq6uqtvYS24bHY0liIndZ7VKibfTqXdAjmswS/8uf9WJqvrkTmdFwj5OlZCeEIOOAwmCELrr2Bg2loI=&amp;lt;/X509Certificate&amp;gt;
                &amp;lt;/X509Data&amp;gt;
            &amp;lt;/KeyInfo&amp;gt;
        &amp;lt;/Signature&amp;gt;
        &amp;lt;saml:Subject&amp;gt;
            &amp;lt;saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"&amp;gt;ldo@securenvoy.com&amp;lt;/saml:NameID&amp;gt;
            &amp;lt;saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"&amp;gt;
                &amp;lt;saml:SubjectConfirmationData Recipient="https://cloudinfra-gw.portal.checkpoint.com/api/saml/sso"
                                              NotOnOrAfter="2025-02-13T14:47:06.8460558Z"
                                              InResponseTo="_04c64b9513de19afe615"
                                              /&amp;gt;
            &amp;lt;/saml:SubjectConfirmation&amp;gt;
        &amp;lt;/saml:Subject&amp;gt;
        &amp;lt;saml:Conditions NotBefore="2025-02-08T14:47:06.8460585Z"
                         NotOnOrAfter="2025-02-13T14:47:06.8460588Z"
                         &amp;gt;
            &amp;lt;saml:AudienceRestriction&amp;gt;
                &amp;lt;saml:Audience&amp;gt;f1f35e8e-3aa5-4fd7-96a9-69259dba2c8d.cloudinfra.checkpoint.com&amp;lt;/saml:Audience&amp;gt;
            &amp;lt;/saml:AudienceRestriction&amp;gt;
        &amp;lt;/saml:Conditions&amp;gt;
        &amp;lt;saml:AuthnStatement AuthnInstant="2025-02-11T02:47:06.8460604Z"
                             SessionIndex="_41d43c47-b69c-4434-b3ca-3021232a3d09"
                             &amp;gt;
            &amp;lt;saml:AuthnContext&amp;gt;
                &amp;lt;saml:AuthnContextClassRef&amp;gt;urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport&amp;lt;/saml:AuthnContextClassRef&amp;gt;
            &amp;lt;/saml:AuthnContext&amp;gt;
        &amp;lt;/saml:AuthnStatement&amp;gt;
        &amp;lt;saml:AttributeStatement&amp;gt;
            &amp;lt;saml:Attribute Name="groups"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
                            &amp;gt;
                &amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;Everyone&amp;lt;/saml:AttributeValue&amp;gt;
            &amp;lt;/saml:Attribute&amp;gt;
            &amp;lt;saml:Attribute Name="urn:mace:dir:attribute-def:userId"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
                            &amp;gt;
                &amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;67768004&amp;lt;/saml:AttributeValue&amp;gt;
            &amp;lt;/saml:Attribute&amp;gt;
            &amp;lt;saml:Attribute Name="identity/claims/givenname"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
                            &amp;gt;
                &amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;Lan&amp;lt;/saml:AttributeValue&amp;gt;
            &amp;lt;/saml:Attribute&amp;gt;
            &amp;lt;saml:Attribute Name="identity/claims/name"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
                            &amp;gt;
                &amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;Do&amp;lt;/saml:AttributeValue&amp;gt;
            &amp;lt;/saml:Attribute&amp;gt;
            &amp;lt;saml:Attribute Name="identity/claims/emailaddress"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
                            &amp;gt;
                &amp;lt;saml:AttributeValue xsi:type="xsd:string"&amp;gt;ldo@securenvoy.com&amp;lt;/saml:AttributeValue&amp;gt;
            &amp;lt;/saml:Attribute&amp;gt;
        &amp;lt;/saml:AttributeStatement&amp;gt;
    &amp;lt;/saml:Assertion&amp;gt;
&amp;lt;/Response&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for looking into this issue&lt;/P&gt;&lt;P&gt;Lan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 02:51:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/240885#M443</guid>
      <dc:creator>donguyenthanhla</dc:creator>
      <dc:date>2025-02-11T02:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSO - Generic SAML Server - 504 Gateway Time-out</title>
      <link>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/240921#M445</link>
      <description>&lt;P&gt;The fact is you're getting some sort of SAML response.&lt;BR /&gt;TAC will need to be involved to troubleshoot further.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:31:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/240921#M445</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-11T15:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSO - Generic SAML Server - 504 Gateway Time-out</title>
      <link>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/240926#M446</link>
      <description>&lt;P&gt;One issue I see in this response is that the&amp;nbsp;&lt;STRONG&gt;urd:mace:dir:atttribute-def:userId&amp;nbsp;&lt;/STRONG&gt; value is not set to Email. Your response shows another value rather than passing the email address back to Infinity Portal. While the Infinity Port IdP settings ask for that to be set to &lt;STRONG&gt;User Id&lt;/STRONG&gt;, I've found in previous testing that the identity provider needs to set this to be the email address.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If setting this to Email from within the IDP doesn't work, I also agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; and recommend opening a TAC case to further troubleshoot.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:58:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/240926#M446</guid>
      <dc:creator>masher</dc:creator>
      <dc:date>2025-02-11T15:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSO - Generic SAML Server - 504 Gateway Time-out</title>
      <link>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/242361#M465</link>
      <description>&lt;P&gt;Hi Masher&lt;/P&gt;&lt;P&gt;I try as you mentioned but still&amp;nbsp;504 Gateway Time-out is returned. Please find screenshot attached.&lt;/P&gt;&lt;P&gt;Please could you share how I can open a&amp;nbsp;&lt;SPAN&gt;TAC case?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;BR /&gt;Lan&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 08:56:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/242361#M465</guid>
      <dc:creator>donguyenthanhla</dc:creator>
      <dc:date>2025-02-26T08:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSO - Generic SAML Server - 504 Gateway Time-out</title>
      <link>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/242459#M466</link>
      <description>&lt;P&gt;If you have a support contract with Check Point: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;BR /&gt;Otherwise, you will need to work with your reseller.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 17:33:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/SSO-Generic-SAML-Server-504-Gateway-Time-out/m-p/242459#M466</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-26T17:33:11Z</dc:date>
    </item>
  </channel>
</rss>

