Symptom
When attempting to modify the SAML redirect URLs in the "Manage SAML SSO settings" section of SuccessFactors, you may encounter the error message "Failed to update asserting party. Validate fail."
Environment
SAP SuccessFactors HXM Suite
Reproducing the Issue
- Access the instance
- Go to "Manage SAML SSO setting"
- Click to edit the SAML configuration
- Select any URL, for example : "Redirect URL when session timeout"
- Add the URL
- Click "Done"
- Error appears "Failed to update asserting party. Validate fail"
Cause
The alert message means that the certificate is old and expired on IDP side.
Resolution
Upload Certificate to IAS Admin Console by following the steps below:
- Click on "Identity providers"
- Click on "Coorporate Identity Providers"
- Select your IAS - IDP integration
- Click on "SAML 2.0 Configuration"
- Under "Signing Certificate" click on "Add"
- Browse for your certificate click on "Add", then in "Save"
Note: If the default certificate is already valid and not expired, then you might also have an old certificate listed that is expired. This old certificate will need to be deleted, only then you will be able to change the redirect URL in "Manage SAML SSO setting"
See Also
Keywords
Failed to update asserting party. Validate fail, Manage SAML Settings, REDIRECT URLS , KBA , LOD-SF-PLT-IAS , Identity Authentication Services (IAS) With BizX , How To
Product
Attachments
Pasted image.png |
Pasted image.png |
Pasted image.png |
Pasted image.png |
Pasted image.png |
Pasted image.png |
Pasted image.png |
Pasted image.png |