Federation Request is Looping

Document ID : KB000115526
Last Modified Date : 21/09/2018
Show Technical Document Details
Issue:
Federation request is looping between the Authentication URL (redirect.jsp) and saml2sso URL.  The Web Agent error log shows the following error:

Agent failed to process request with return code: '-1'.
Cause:
The Access Gateway agent was configured to use an ACO (Agent Configuration Object) that was not based on the SPSDefaultSettings ACO template.  This can cause odd behavior around authentications that take place on the Access Gateway Web Agent.
Resolution:
The ACO used by the Access Gateway Agent should always be based on the SPSDefaultSettings ACO template.  Rebuilding the ACO based on this template resolved the issue.