SAP Knowledge Base Article - Preview

2465658 - Renew IDP signing certificate in Service Provider on AS Java without downtime

Symptom

  • SAML2.0 has been configured using AS Java as the Service Provider (SP).
  • The signing certificate of the Identity Provider (IDP), such as ADFS, has been renewed and needs to be imported into the SP without downtime.

"*Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental.


Read more...

Environment

SAP NetWeaver Java system 7.3 and higher

Product

SAP NetWeaver Application Server for Java all versions

Keywords

saml2, saml2.0, sso, single sign on, samlrequest, samlresponse, signature, encrypt, decrypt, Primary Signing Certificate, Signiture validation of SAML2Assertion failed, Rejected signed Assertion, Primary certificate for signature validation is not configured or it is missing in the keystore, Signature, ad fs, adfs 2.0, adfs 3.0, Active Directory Federation Services, AdfsCertificate , KBA , BC-JAS-SEC-SML , JAVA SAML 1.1 and 2.0 , BC-JAS-SEC , Security, User Management , How To

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.