SAP Knowledge Base Article - Preview

3538661 - [AS Java] SAML authentication does not work after renewing IDP signing certificate

Symptom

After renewing the IDP signing certificates directly in the Keystore view of SAML2, SSO stops working.

When analyzing Troubleshooting Wizard (TSHW) traces, the following error messages can be seen:

Keystore view with alias [<alias name>] not found.

Signature of the SAML2 protocol token cannot be validated because neither primary nor secondary certificates are available in the configuration


Read more...

Environment

SAP NetWeaver Application Server for Java

Product

SAP NetWeaver Application Server for ABAP all versions

Keywords

SAML2, authentication, certificate renewal, SSO, Single Sign-On, JAVA SAML 1.1, JAVA SAML 2.0, signature, renew signing certificate , KBA , BC-JAS-SEC-SML , JAVA SAML 1.1 and 2.0 , BC-JAS-SEC-LGN , Logon, SSO , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.