SAP Knowledge Base Article - Public

2879161 - How to update the SAML IdP Signing Certificate or Metadata.xml in SAP Analytics Cloud (SAC)

Symptom

  • System owner of SAP Analytics Cloud tenant received the message: Identity Provider signing certificate will expire in 30 days.
  • How to update the Identity Provider metadata with renewed signing certificate in SAC.
  • How to update the FederationMetadata.xml

Environment

SAP Analytics Cloud with Custom SAML enabled

Reproducing the Issue

Cause

Resolution

Steps if SAP Analytics Cloud cannot be accessed:

Please ask the System Owner to follow the steps in the KBA 2908073 - How to use the IdP Admin Tool to make changes to IdP Configuration in SAP Analytics Cloud when no access is available to the tenant

Steps if SAP Analytics Cloud can be accessed:

If the custom IdP certificate is expired or is about to expire, there is new feature to update the SAML IDP Signing Certificate from 2019.22.

  • Details in Help guide below:
    Updating the SAML IdP Signing Certificate

  • You must have the metadata file that contains the new certificate from your custom IdP, and you must be logged into SAP Analytics Cloud before your IdP switches over to using the new certificate. You must be the System Owner in SAP Analytics Cloud.

      1. Go to (Main Menu) System Administration Security
      2. Select (Edit)
      3. Under Step 2, select Update and provide the new metadata file
      4. Select (Save) and confirm the change to complete the update. The update will take effect within two minutes

NOTE: There are two buttons: Upload and Update. You need to use Update button to update the metadata for your current IdP, and it does not have to redo SAML trust verification. If you use Upload button to update the metadata for your current IdP, you will see a red box around the Name box, when you click it you will see the warning message: Your system is currently using this ID. Please configure a new ID on your identity provider and then upload the updated XML file. Choose Upload only if you want to upload a new or different identity provider.

See Also

Your feedback is important to help us improve our knowledge base.

Keywords

SAP Cloud for Planning, sc4p, c4p, cforp, cloudforplanning, Cloud for Analytics, Cloud4Analytics, CloudforAnalytics, Cloud 4 Planning, BOC, SAPBusinessObjectsCloud, BusinessObjectsCloud, BOBJcloud, BOCloud., SAC, SAP AC, Cloud-Analytics, CloudAnalytics, SAPCloudAnalytics,Error, Issue, System, Data, User, Unable, Access, Connection, Sac, Connector, Live, Acquisition, Up, Set, setup, Model, BW, Connect, Story, Tenant, Import, Failed, Using, Working, SAML, SSO, sapanalyticscloud, sap analytical cloud, sap analytical cloud, SAC, ADFS, Azure AD, metadata.xml, FederationMetadata.xml , KBA , LOD-ANA-ADM , SAC Administration , LOD-ANA-AUT , SAC Authentication / Login , Problem

Product

SAP Analytics Cloud 1.0