SAP Knowledge Base Article - Preview

2465658 - Renew IDP signing certificate in Service Provider on AS Java without downtime


You have configured SAML2.0 using AS Java as Service Provider (SP).
You have renewed signing certificate of Identity Provider (IDP) like ADFS and you want to import the same one into SP without downtime.



Using AS Java as SAML 2.0 Service Provider
SAP NetWeaver Java system 7.3 and higher


SAP NetWeaver 7.3 ; SAP NetWeaver 7.4 ; SAP NetWeaver 7.5 ; SAP enhancement package 1 for SAP NetWeaver 7.3


saml2, saml2.0, sso, single sign on, samlrequest, samlresponse, signature, encrypt, decrypt, Primary Signing Certificate, Signiture validation of SAML2Assertion failed, Rejected signed Assertion, Primary certificate for signature validation is not configured or it is missing in the keystore, Signature, ad fs, adfs 2.0, adfs 3.0, Active Directory Federation Services, AdfsCertificate , KBA , BC-JAS-SEC-SML , JAVA SAML 1.1 and 2.0 , BC-JAS-SEC , Security, User Management , How To

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.