DRM-SAML redirect failure after IDP authentication in AEM Forms JEE
If you’re not redirected to the secure document after authenticating via your Identity Provider (IDP), check your SAML and DRM integration settings in AEM Forms JEE. Ensure the redirect URL is correctly configured and the secure document is accessible post-authentication.
Description description
Environment
-
Adobe Experience Manager (AEM) Forms
-
Version: 6.5
Issue/Symptoms
When using AEM Forms Document Security (Rights Management) to secure a PDF, you encounter a redirect failure after authenticating via the Identity Provider (IDP) in Adobe Acrobat or Reader.
Instead of being redirected to the secure document, you are sent back to the um/login screen and see the following error message: You have reached this page because cookies might not be enabled on your browser. Please enable the cookies and then re-access the LiveCycle application.
Resolution resolution
Adobe Acrobat and Reader support SAML 2.0 authentication for accessing RM-secured PDFs and applying RM policies through AEM Forms Document Security when configured correctly.
Note: Only a system administrator who is familiar with the AEM forms product and XML should consider modifying the configuration file.
To ensure proper redirection to secure documents using SAML 2.0 in Adobe Acrobat or Reader:
-
Ensure extended authentication is enabled in the Rights Management configuration. To validate if extended authentication configuration is visible under SSO:
Navigate to the Administration Console
>Home>Services>Document Security>Configuration>Server Configuration. Ensure that the Allow Extended Authentication option is selected and that the Extended Authentication Landing URL has been entered. -
Check the configuration in the
config.xmlfile. In the Administration Console>Home>Settings>User Management>Configuration>Import and Export Configuration Files>Export. Export theconfig.xmlfile. For detailed steps, refer to Importing and exporting the configuration file in the AEM 6.5 User Guide. Open theconfig.xmlfile in a text editor and check whether the following entry is present under theSSOnode:
<entry key="rm-ea-w" value="/edc/extendedauthentication/welcome.jsp"/>
3. If the entry is missing edit the config.xml file to include this entry key.
4. Navigate back to the Administration Console > Home > Settings > User Management > Configuration > Import and Export Configuration Files > Import. Upload the modified config.xml file. For detailed steps, refer to Importing and exporting the configuration file in the AEM 6.5 User Guide.
5. Restart the server. You should now be redirected back to the secure document when opening it in Acrobat.
If issues persist, contact Adobe support.
Related reading
Configuring Secure Administration Settings for AEM Forms on JEE in the AEM 6.5 User Guide.