Troubleshooting: Service Provider Reports an Invalid Certificate After Importing the Exported SAML Signing Cert

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    After exporting a realm's SAML signing certificate from the Post Authentication tab and importing it into a service provider (SP), the SP reports an invalid certificate error.

     

    Cause

    Some service providers require the certificate in a different format than the one the Admin Console exports by default.

     

    Resolution:

    To resolve this:

    1. On the appliance, open the Certificates console (for example, run certlm.msc).
    2. Expand Personal and find the realm's signing certificate.
    3. Right-click the certificate, then select All Tasks > Export.
    4. Select No, do not export the private key.
    5. Select Base-64 encoded X.509 (.cer).
    6. Complete the export, then import this certificate into the service provider.




     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.