SAP Knowledge Base Article - Public

3508802 - Certificate error when accessing the SAC URL in a parallel tab - Story troubleshooting

Symptom

  • While troubleshooting blank/loading screen issues when creating/running Story reports via Report Center, you followed KBA 3508799 and encountered an error when accessing the SAC URL in a parallel tab.
  • After SSO Certificate update Story reports were not accessible anymore.

Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental.

Environment

  • SAP SuccessFactors HCM Suite
    • Analytics & Reporting (Ad Hoc, YouCalc, ORD)
      • Story Reports

Reproducing the Issue

  1. Follow the KBA 3508799 - How to collect SAML traces for Story troubleshooting
  2. When opening the SAC URL in a parallel tab, as described in the KBA, one of the errors below is displayed:

    OR

    OR

Using SAML traces to validate this:

  1. Copy the X509Certificate being displayed in the SAC SAML call (same one we use to validate the UUID). 3508799
  2. In a new browser tab, go to your IAS tenant’s metadata URL. The format is https://<IAS-Tenant-ID>.accounts.ondemand.com/saml2/metadata
    1. If they match, the certificate is correct.
    2. If they do not match, follow the Resolution steps.

Cause

The Identity Authentication service (IAS) is signing the SAML assertion with a certificate that SAP Analytics Cloud (SAC) does not trust. SAC has a pre-configured certificate in its trust store, and when the incoming SAML response is signed with a different certificate, SAC rejects the login attempt for security reasons.

This mismatch typically happens for one of two reasons:

  • The default signing certificate for the entire IAS tenant was recently renewed, but the trust configuration within SAC was not updated. Therefore, IAS is using the new certificate, while SAC still expects the old one.
  • The "SF Analytics - <Company ID>" application in IAS has been configured to use a specific, non-default signing certificate (found under IAS > Applications > SF Analytics... > SAML 2.0 Configuration > Signing Certificate). This specific certificate is incorrect/outdated, causing it to differ from what SAC is configured to trust.

Resolution

The "SF Analytics - <Company ID>" application in IAS is managed by an automated process and should not be modified manually. To resolve the configuration mismatch, the SAC application must be deleted from IAS and then recreated using the official backend job.

Important: Do not attempt to fix this by manually editing the application in IAS. Follow the steps below precisely.

Step 1: Customer Action - Delete the IAS Application

  1. The customer’s IAS administrator must delete the existing application.
  2. Log in to the Identity Authentication service (IAS) tenant as an administrator.
  3. Navigate to Applications & Resources > Applications.
  4. Find the application named SF Analytics - <company ID>
  5. Select the application and click Delete. Confirm the deletion.

Step 2: SAP Support Action - Re-create the Configuration 

  1. After step 1 is completed, access the corresponding SuccessFactors instance in Provisioning.
  2. Navigate to Manage Scheduled Jobs.
  3. Run the "Update IAS/IPS configuration for Story Reports" job.

    Note: Only SAP Partners or SAP Support have access to SuccessFactors Provisioning. If you are a customer, open a case for LOD-SF-ANA-SAC and request Support help to run required job.

This job will automatically re-create the "SF Analytics - <Company ID>" application in IAS with the correct, up-to-date configuration, including the valid signing certificate. This re-establishes the trust and resolves the SSO error.

See Also

Keywords

The digital signature of the received SAML2 message is invalid, certificate, SAC, story, stories, blank screen, loading screen, report center, Identity Provider could not process the authentication request received. Delete your browser cache and stored cookies, and restart your browser, Response doesn't have any valid assertion which would pass subject validation, login error, fail to login to sap analytics cloud, Internal Server Error , KBA , LOD-SF-ANA-SAC , Stories in People Analytics , LOD-SF-ANA-SAC-IAS , IAS configurations , Problem

Product

SAP SuccessFactors HCM Suite all versions ; SAP SuccessFactors Platform all versions