Logon on Nextcloud with Safari against ADFS with 2FA does not work

Hi folks,

we’ve set up Windows ADFS (Server 2022) and configured the privacyIDEA plugin. Everything works fine with Chrome/Edge/Firefox on Windows 10, but not an iOS Device with Safari (neither iPhone, iPad nor MacOS are working). While running the same on an Mac Mini with Firefox installed the system works as expected.

The error message in Nextcloud (24.0.5.1) is:

Sep 20 16:39:12 debncl3 Nextcloud[59045]: {"reqId":"AV6ebtqTgtI274IOBJZD","level":4,"time":"2022-09-20T14:39:12+00:00","remoteAddr":"10.142.xxx.x","user":"--","app":"user_saml","method":"POST","url":"/nextcloud/apps/user_saml/saml/acs","message":"invalid_response","userAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.0 Safari/605.1.15","version":"24.0.5.1","data":{"app":"user_saml"}}
Sep 20 16:39:12 debncl3 Nextcloud[59045]: {"reqId":"AV6ebtqTgtI274IOBJZD","level":4,"time":"2022-09-20T14:39:12+00:00","remoteAddr":"10.142.xxx.x","user":"--","app":"user_saml","method":"POST","url":"/nextcloud/apps/user_saml/saml/acs","message":"The status code of the Response was not Success, was Responder","userAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.0 Safari/605.1.15","version":"24.0.5.1","data":{"app":"user_saml"}}

Here is a screeshot from the user-interface:

nextcloud-saml-error-safari

Does anyone has an idea?

Best regards
Stephan

I would try the nextcloud community!

Well, that might be a way. But please keep in mind that while disabling the privacyIDEA-ADFS plugin the access on Nextcloud works even with Safari. The problem exist with the combination of an enabled privacyIDEA-ADFS plugin and Safari only.

Regards
Stephan