SAP Knowledge Base Article - Public

3635337 - Preventing expired custom IdP certificate in SAP Datasphere

Symptom

  • How to update the SAML IdP Certificate
  • How to update the SAML certificate when the system owner is not available 
  • How to update the SAML certificate using the Identity Provider Administration

Environment

SAP Datasphere

Reproducing the Issue

Datasphere home screen displays "no authorized" when attempting to access it.

Cause

Datasphere Tenant SAML Certificate Expired

Resolution

How to update the SAML IdP Certificate

  1. Upload a new SAML metadata .xml file which contains a new signing certificate
  2. From the Datasphere home screen, go to system - administration - security
  3. Select edit
  4. Under step 2, select Update and provide the new metadata file
  5. Select save and confirm the change to complete the update

How to update the SAML certificate when the system owner is not available 

  1. When the IDP certification expires and the system owner is not available to upload a new one, as a workaround to keep the system running, a case needs to be created for SAP Support under the component DS-SEC-AUTN to proceed with the upload.
  2. In the case attachment is required to have the XML metadata file, even if there are no changes in the metadata configuration

How to update the SAML certificate using the Identity Provider Administration

  1. Sign up into the Identity Provider Administration Tool.
  2. On the card for the tenant that you want to update, select "Repair IdP."
  3. Select Upload new metadata for the current custom IdP.
  4. Click Browse to select the new SAML metadata .xml file for your current custom IdP.
  5. Click Upload File. After the upload is successful, it can take up to five minutes for the new metadata file to be applied.
  6. Click Step 3 to proceed to the validation step.
  7. Click Log into SAP Datasphere to open a new tab

See Also

Keywords

out of office, SAML CERT, enable default, DS, Idp Admin Tool, SSO. , KBA , DS-SEC-AUTN , Authentication: SSO/SAML, OAuth Client , How To

Product

SAP Datasphere all versions