SAP Knowledge Base Article - Public

3768376 - Getting HTTP Status 500 – Internal Server Error when trying to log on to SAP Analytics Cloud (SAC) tenant via legacy custom IdP

Symptom

  • Getting HTTP Status 500 – Internal Server Error when trying to log on to SAP Analytics Cloud (SAC) tenant via legacy custom IdP
  • The following error could be observed in HAR file:
    • Request URL: https://<SAC FQDN>/sso/login/callback?error=access_denied&error_description=Invalid+status+%5Burn%3Aoasis%3Anames%3Atc%3ASAML%3A2.0%3Astatus%3AResponder%5D+for+SAML+response+<...> 
    • Response:
      • Status:500
      • Content: Internal Server Error

You may have received an email urgently requesting action:

Environment

  • SAP Analytics Cloud (Enterprise Edition), running on Cloud Foundry (CF)
  • Legacy Custom IdP enabled (see SAC Help)

Reproducing the Issue

  1. Access SAC tenant which has legacy custom IdP enabled.
  2. Enter credential in IdP logon page.
    • Error happens when redirecting back to SAC

Cause

  • In the HAR file, you may find another reqeust https://<...>.authentication.us10.hana.ondemand.com/saml/SSO/alias/<...> which contains SAML response.
  • By decoding the SAML response, you could find the following information
        <samlp:Status>
            <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder"/>
            <samlp:StatusMessage>
                Unable to verify the signature
            </samlp:StatusMessage>
        </samlp:Status>
  • It means that  the custom IdP rejects the SAML request including a new X509Certificate, which is different from the previous X509Certificate uploaded with SAC SAML metadata into IdP (even though that it has not yet expired).

Resolution

If you received an email about a new signing certificate in SAC metadata, please act before August 2, 2026 to avoid login disruptions.                                                                                           

While you still have access, you can also update your Identity Provider with the latest metadata by:    
    1. From the side navigation, go to System  -> Administration  ->  Security.
    2. Select Edit.
    3. In the Authentication Method area, select SAML Single Sign-On (SSO) if it is not already selected.
    4. In Step 1, select Download and save the metadata file.An SAP Analytics Cloud metadata file will be saved.
    5. Upload the SAP Analytics Cloud metadata file to your SAML IdP. The file includes metadata for SAP Analytics Cloud, and is used to create a trust relationship between your SAML Identity Provider and your SAP Analytics Cloud system.

If you no longer have access to the system, please use the workaround:

  1. Download new SAC SAML metadata from <tenantName>.authentication.<datacenter>.hana.ondemand.com/saml/metadata 
    • e.g. tenant URL companyA.us10.sapanalytics.cloud would use companyA.authentication.us10.hana.ondemand.com/saml/metadata
  2. Update the new SAC SAML metadata into your IdP

See Also

Your feedback is important to help us improve our knowledge base.

Keywords

SAP Cloud for Planning, sc4p, c4p, cforp, cloudforplanning, EPM-ODS, Cloud for Analytics, Cloud4Analytics, CloudforAnalytics, Cloud 4 Planning, BOC, SAPBusinessObjectsCloud, BusinessObjectsCloud, BOBJcloud, BOCloud., SAC, SAP AC, Cloud-Analytics, CloudAnalytics, SAPCloudAnalytics, directory, error, 500, logoff, logout, exit, saml, saml2, saml, sso, Cloud-Analytics,  slo, acs, log out, log in,access_denied,/sso/login/callback, Unable to verify the signature , KBA , LOD-ANA-AUT , SAC Authentication / Login , Problem

Product

SAP Analytics Cloud 1.0