Keycloak as SAML IdP for Palo Alto

Hi Everyone!

I’m a bit new to Keycloak and have hit a roadblock here. Hoping for some advice or maybe someone has gotten this to work themselves.

I’m attempting to configure our Palo Alto Globalprotect gateway to authenticate through Keycloak.
I’ve set up the Authentication profile and exported the client data. A client with the XML file from Palo Alto has been created.

When I attempt to use the Globalprotect gateway, it redirects to our Keycloak realm, but has a window stating “We are sorry… Invalid request”

On the server side, I get an error : error=invalid_saml_response, reason=invalid_saml_response