SAP Knowledge Base Article - Public

3351218 - Manage SAML SSO Settings alert "Failed to update asserting party. Validate fail"

Symptom

When attempting to modify the SAML redirect URLs in the "Manage SAML SSO settings" section of SuccessFactors, you may encounter the error message "Failed to update asserting party. Validate fail."

Environment

SAP SuccessFactors HXM Suite

Reproducing the Issue

  1. Access the instance
  2. Go to "Manage SAML SSO setting"
  3. Click to edit the SAML configuration
  4. Select any URL, for example : "Redirect URL when session timeout" 
  5. Add the URL
  6. Click "Done"
  7. Error appears "Failed to update asserting party. Validate fail"

Cause

The alert message means that the certificate is old and expired on IDP side.

Resolution

Upload Certificate to IAS Admin Console by following the steps below:

  1. Click on "Identity providers"
  2. Click on "Coorporate Identity Providers"
  3. Select your IAS - IDP integration
  4. Click on "SAML 2.0 Configuration"
  5. Under "Signing Certificate" click on "Add"
  6. Browse for your certificate click on "Add", then in "Save"

Note: If the default certificate is already valid and not expired, then you might also have an old certificate listed that is expired. This old certificate will need to be deleted, only then you will be able to change the redirect URL in "Manage SAML SSO setting"

See Also

2768478 - [SSO] How to change redirect URLs for Single Sign On

2674588 - SSO - Manage SAML SSO Settings

Keywords

Failed to update asserting party. Validate fail, Manage SAML Settings, REDIRECT URLS , KBA , LOD-SF-PLT-IAS , Identity Authentication Services (IAS) With BizX , How To

Product

SAP SuccessFactors HCM suite all versions

Attachments

Pasted image.png
Pasted image.png
Pasted image.png
Pasted image.png
Pasted image.png
Pasted image.png
Pasted image.png
Pasted image.png