Symptom
SF login fails after 2H2024 release due to certificate not being updated on Corporate IdP side.
Environment
SAP SuccessFactors HCM Suite
Reproducing the Issue
- Open SF login URL
- Enter username/password and pass on corporate IdP authentication
- You will see login failing
Cause
With 2411 release, a new SSO certificate is available and can be used by customers to renew SF SSO certificate on corporate IdP, the renewal itself is a manual process as per Renewal of SAP SuccessFactors HCM suite Single-Sig... - SAP Community.
However, it is required that the update on corporate IdP is done before enabling the "SSO Certificate Renewed" under "Admin Center > SAML SSO Settings".
The login fail will occur then when corporate IdP side didn't update the new certificate.
Resolution
- Go to "Admin Center > SAML SSO Settings"
- Check if the "SSO Certificate Renewed" flag is enabled
> > If the flag is enabled:
- Use below URL to get new public certificate: https://<SF Customer Facing Host>/saml2/spnewcert?company=<company_id>
- The corporate IdP side needs to be update with this public certificate
> > If the flag is disabled:
- Please check the SF SSO certificate expiration date in corporate IdP:
- If it is June 2, 2025, then it is the old certificate, you should update it
- If expiration date is 2029, then you are using the new certificate already and you can enable the "SSO Certificate Renewed" flag under SAML SSO Settings
For Product support team, please check internal memo.
See Also
- Blog regarding SSO certificate renewal: https://community.sap.com/t5/product-and-customer-updates/renewal-of-sap-successfactors-hcm-suite-single-sign-on-sso-certificate/ba-p/13727406
Keywords
INC10073563, sso, Certificate, Renewed, Corporate IdP, SSO, login, failed, sf, SF, successfactors, SuccessFactors. , KBA , LOD-SF-PLT-SEL , SSO Errors & Logs , How To