Skip to main content
Announcements
Qlik Connect 2024! Seize endless possibilities! LEARN MORE

Integrating SAML with Qlik Sense Enterprise

No ratings
cancel
Showing results for 
Search instead for 
Did you mean: 
Troy_Raney
Digital Support
Digital Support

Integrating SAML with Qlik Sense Enterprise

Last Update:

Feb 25, 2021 8:04:48 AM

Updated By:

Sonja_Bauernfeind

Created date:

Sep 20, 2019 3:40:25 AM

This session will address:

  • Authentication Overview
  • Pre-reqs for successful deployment
  • Demo of virtual proxy setup and workflow
  • Troubleshooting common issues





Qlik Sense: Information needed to Troubleshoot SAML SSO related issues: Qlik Sense: Information needed to Troubleshoot SAML SSO related issues
SHA-256 and Converting the Cryptographic Service Provider Type: SHA-256 and Converting the Cryptographic Service Provider Type
Qlik Sense: SAML GET request invalid format: Qlik Sense: SAML GET request invalid format



Q&A - Integrating SAML with Qlik Sense Enterprise


Q: 
Is it possible to tether with an existing SSO, e.g. similar to the 'sign-up using Facebook/ Google/ Linked-In' without additional purchases?
A: That kind of setup is solely done on the Identity Provider side and additional settings are usually not required on the Qlik Sense side, so it may be possible or not based on the Identity Provider used. Please check the documentation of your Identity Provider for more details.

Q: If I'm using one IdP Entity ID for a SAML virtual proxy, can I use the same IdP Entity ID for setting up SAML auth. for NPrinting web console and NPrinting NewsStand?
A: Yes, but not the same SP Entity ID. Most of IdP won’t let you create 2 relying party trusts with the same SP Entity ID. (The Entity ID setting on the Qlik Sense virtual proxy is the SP Entity in this case).

Q: QlikView allows the domain/user to be separated , can this be done with Qlik Sense with SAML?
A: Yes, the domain and the user are 2 separated attributed in the Qlik Sense SAML configuration.

Q: Do you have a comprehensive list with error messages in the trace logs? And the most probable issues related to that?
A: We do not have a full list in a single knowledge base article. However each of the known error messages are documented in a separate knowledge base article on support.qlik.com.

Q: Is it possible to use both IDP and SDP for both QlikView and Qlik Sense Apps?
A: QlikView does not support SAML. If you are referring to QlikView Apps distributed in the Qlik Sense unified hub, those are just links to the QlikView Document on the QlikView Server, so when opening the link, you will need to authenticate to the QlikView Server again even if you are already authenticated in Qlik Sense.
For QlikView apps hosted in Qlik Sense on Kubernetes (November 2019 release), this extra-step of re-authenticating to QlikView will not be necessary anymore.

Q: I have 2 front-end load balanced web proxies. Can I used the same ADFS/SAML trust for both or do I have to create 2 separate trusts
A: If the same third-party certificate is applied on all Qlik Sense proxies, and the virtual proxy added for SAML are linked to all Qlik Sense proxies, and that the external URL from the end user is a single URL, then a single trust is sufficient to accomplish this scenario.

Q: Is it possible to mix SSO and SAML?
A: SSO (Single Sign-on) is a concept that the user does not have to input his credentials and is not a type of authentication in itself. If you mean mix Windows authentication and SAML authentication, yes that is possible, but it will require two separate virtual proxies created in Qlik Sense.
 

Labels (1)
Comments
BoB_Qlik_Support
Contributor
Contributor

What should be the load balancing node for the virtual proxy created for saml sign in.

Should it be only central node or it can be any rim node ?

Regards,

Jyoti

Sonja_Bauernfeind
Digital Support
Digital Support

Hello,

The virtual proxy used for the SAML sign-in can be hosted on either the central node or a rim node.

All the best,
Sonja 

BoB_Qlik_Support
Contributor
Contributor

Hello @Sonja_Bauernfeind , Thanks for the reply.

what should be the linked proxy .

When I try to link it with central node , SSO works .

But if the link proxy is any RIM node , SSO doesnt work .

Is there any restriction for this . I am using Azure AD.

 

Sonja_Bauernfeind
Digital Support
Digital Support

Hello @BoB_Qlik_Support 

I'd recommend posting details about your setup (versions, settings, etc) and what you are attempting to achieve in our Integration forum, including the error you are receiving and information you can extra from the log files.

This may need more investigation than what we can provide in this article. The forum I pointed you at is monitored by our support agents and has an active userbase.

All the best,
Sonja

Contributors
Version history
Last update:
‎2021-02-25 08:04 AM
Updated by: