Stop googling SAP errors. Use our Free Essentials plan instead - no credit card needed. Start Now

Close

How To Fix WSS030 - No unique mapping for SAML authentication found (Issuer &3)


SAP Error Message - Details

  • Message type: E = Error

  • Message class: WSS - Web Services Security

  • Message number: 030

  • Message text: No unique mapping for SAML authentication found (Issuer &3)

  • Show details Hide details
  • What causes this issue?

    No unique mapping for SAML authentication found (Issuer &V3&)

    System Response

    Authentication failed

    How to fix this error?

    Please ensure the mapping is unique. You may check the mappings in
    transaction SM30, view VUSREXTID, type SA. For more information on
    mapping check the documentation and note 1254821.

    The system issues an error message and will not allow you to continue with this transaction until the error is resolved.

    SAML Issuer: &V3&
    Certificate DN: &V1&&V2&
    If you use report RSUSREXTID for maintaing the mapping, the following
    information if usefull:
    Type of External ID:SA
    Prefix of External Name: &V4&
    Name of Issuer: &V1&&V2&

    Procedure for System Administrators


    Error message extract from SAP system. Copyright SAP SE.


Smart SAP Assistant

  • What is the cause and solution for SAP error message WSS030 - No unique mapping for SAML authentication found (Issuer &3) ?

    SAP Error Message:
    WSS030 No unique mapping for SAML authentication found (Issuer &3)


    Cause

    This error occurs during SAML (Security Assertion Markup Language) authentication in SAP when the system tries to identify a user based on the SAML assertion but finds multiple or no unique mappings for the given SAML issuer. Specifically:

    • The SAML issuer (the Identity Provider, IdP) sent an assertion.
    • SAP tries to map the SAML assertion to a user in its system.
    • The mapping configuration in SAP is ambiguous or missing, resulting in no unique user mapping.
    • This can happen if:
      • Multiple users are mapped to the same SAML issuer and attribute.
      • The mapping configuration is incomplete or incorrect.
      • The SAML assertion does not contain the expected attributes or identifiers.
      • The SAML issuer name in the assertion does not match the configured issuer in SAP.

    Explanation

    In SAP SAML authentication, the system uses a mapping configuration to link the SAML assertion attributes (like NameID, email, or other attributes) to SAP user IDs. This mapping is defined in the SAP system (e.g., in transaction SAML2 or via configuration in the SAML 2.0 Identity Provider setup).

    If the system cannot find a unique user mapping for the given issuer and attribute, it cannot authenticate the user, hence the error.


    Solution

    1. Check SAML 2.0 Configuration in SAP:

      • Go to transaction SAML2.
      • Check the Identity Provider (IdP) configuration.
      • Verify the Issuer name matches exactly the issuer in the SAML assertion.
      • Check the User Mapping settings:
        • Ensure that the attribute used for mapping (e.g., NameID, email, or a custom attribute) is correctly configured.
        • Make sure the mapping is unique and points to exactly one SAP user.
    2. Verify User Mapping:

      • Check if multiple SAP users are mapped to the same SAML attribute value.
      • If yes, adjust the mapping so that each SAML attribute value corresponds to a unique SAP user.
    3. Check the SAML Assertion:

      • Use SAML tracing tools (e.g., browser SAML tracer plugins) to inspect the SAML assertion.
      • Confirm the issuer and attributes sent by the IdP.
      • Ensure the attributes used for mapping are present and correctly formatted.
    4. Adjust or Create User Mapping:

      • If no mapping exists, create a new mapping rule in SAP.
      • If multiple mappings exist, refine the mapping criteria to ensure uniqueness.
    5. Synchronize User Data:

      • If user attributes have changed in the IdP, update SAP user master data accordingly.
    6. Check SAP Notes and Documentation:

      • Review SAP Notes related to SAML authentication and this error message for any patches or updates.

    Related Information

    • Transaction: SAML2 — Used to configure SAML 2.0 settings in SAP.
    • SAP Help: SAML 2.0 Authentication in SAP NetWeaver.
    • Common Attributes for Mapping: NameID, email, UserPrincipalName, or custom attributes.
    • SAP Notes: Search for notes related to WSS030 or SAML authentication issues.
    • Tools: Use SAML tracer browser extensions to debug SAML assertions.

    Summary

    Aspect Details
    Cause No unique user mapping found for the SAML issuer and attribute during authentication.
    Effect User cannot be authenticated via SAML; error WSS030 is raised.
    Solution Verify and correct SAML IdP issuer name, user mapping configuration, and SAML assertion.
    Tools SAP transaction SAML2, SAML tracer tools, SAP Notes.

    If you need further assistance, please provide:

    • The SAML assertion details (issuer, attributes).
    • Current SAP SAML mapping configuration.
    • SAP system version and patch level.
    • Do you have any question about this error?


      Upgrade now to chat with this error.


Instant HelpGet instant SAP help. Sign up for our Free Essentials Plan.


Related SAP Error Messages

Click the links below to see the following related messages:

Click on this link to search all SAP messages.


Rating
ERPlingo's SAP support assistant is amazing. Saves me countless hours trying to solve complex SAP issues myself. It's a real game changer!
Rate 1
Thomas Michael
SAP Consultant, Author & Speaker