Symptom
The Identity Provider Signing (IDP) / Single Sign-On (SSO) certificate used to establish trust between Advanced Workflow (Service Provider, SP) and SAP Identity Authentication Service (IAS) / your corporate Identity Provider (IdP) is expiring. The renewal process requires user action to update the SAML 2.0 certificate and metadata in both Advanced Workflow and IAS, otherwise users will be unable to authenticate via SSO.
Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental.
Read more...
Environment
- SAP Sales Performance Management
- Advanced Workflow
Product
SAP Incentive Management all versions
Keywords
Certificate renewal, SSO, Single Sign-On, SAML 2.0, Identity Provider, IdP, IAS, Advanced Workflow, SAP Incentive Management, sp.xml, Integration Panel, metadata file, signing certificate, encryption certificate, IdP configuration, client secret, client ID, certificate expiration, SAML metadata, NameID, Entity ID, authentication, login issue.
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview