<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to re-import the metadata XML file to SAML Configuration of Splunk Cloud? in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-re-import-the-metadata-XML-file-to-SAML-Configuration-of/m-p/631063#M2044</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I need to re-import new XML metaddata to the Splunk Cloud SAML Configuration which is generated for Azure SSO users. The current cert is valid until 19/02/2023. The issue is when I &lt;SPAN&gt;try to import the new xml (federationmetadata.xml) into the SAML configuration in the Splunk&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It constantly&amp;nbsp;encounters the error “There are multiple cert,idepCertPath,idpCert.pem, must be directory"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Try to remove the idpCert.pem in the ./etc/auth/idpCerts/idpCert.pem, and shows Server Error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I don't know how I can find the path (&lt;SPAN&gt; ./etc/auth/idpCerts/idpCert.pem&lt;/SPAN&gt;) in the Splunk cloud as it is not on=premises.&lt;/P&gt;&lt;P&gt;I really need your help as the current valid will expired very soon (19/02/2023)and results&lt;SPAN&gt;&amp;nbsp;in users and admins being locked out of Splunk Cloud.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Any way to fix it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;STRONG&gt;"""urgent&amp;nbsp;to&amp;nbsp;solve"""&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;Many thanks, Goli&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/183919"&gt;@tlam_splunk&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would greatly appreciate it if anyone could help me!&lt;/P&gt;&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;</description>
    <pubDate>Wed, 15 Feb 2023 21:01:30 GMT</pubDate>
    <dc:creator>GoliSH</dc:creator>
    <dc:date>2023-02-15T21:01:30Z</dc:date>
    <item>
      <title>How to re-import the metadata XML file to SAML Configuration of Splunk Cloud?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-re-import-the-metadata-XML-file-to-SAML-Configuration-of/m-p/631063#M2044</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I need to re-import new XML metaddata to the Splunk Cloud SAML Configuration which is generated for Azure SSO users. The current cert is valid until 19/02/2023. The issue is when I &lt;SPAN&gt;try to import the new xml (federationmetadata.xml) into the SAML configuration in the Splunk&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It constantly&amp;nbsp;encounters the error “There are multiple cert,idepCertPath,idpCert.pem, must be directory"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Try to remove the idpCert.pem in the ./etc/auth/idpCerts/idpCert.pem, and shows Server Error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I don't know how I can find the path (&lt;SPAN&gt; ./etc/auth/idpCerts/idpCert.pem&lt;/SPAN&gt;) in the Splunk cloud as it is not on=premises.&lt;/P&gt;&lt;P&gt;I really need your help as the current valid will expired very soon (19/02/2023)and results&lt;SPAN&gt;&amp;nbsp;in users and admins being locked out of Splunk Cloud.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Any way to fix it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;STRONG&gt;"""urgent&amp;nbsp;to&amp;nbsp;solve"""&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;Many thanks, Goli&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/183919"&gt;@tlam_splunk&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would greatly appreciate it if anyone could help me!&lt;/P&gt;&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;</description>
      <pubDate>Wed, 15 Feb 2023 21:01:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-re-import-the-metadata-XML-file-to-SAML-Configuration-of/m-p/631063#M2044</guid>
      <dc:creator>GoliSH</dc:creator>
      <dc:date>2023-02-15T21:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to re-import the metadata XML file to SAML Configuration of Splunk Cloud?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-re-import-the-metadata-XML-file-to-SAML-Configuration-of/m-p/631145#M2047</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/247559"&gt;@GoliSH&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I haven't an answer to your question.&lt;/P&gt;&lt;P&gt;the only hint I have is to open a case to Splunk Support, also because, using Splunk Cloud you (or your customer) have some credits to engage Splunk Professional Services in problems like your.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 07:29:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-re-import-the-metadata-XML-file-to-SAML-Configuration-of/m-p/631145#M2047</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-16T07:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to re-import the metadata XML file to SAML Configuration of Splunk Cloud?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-re-import-the-metadata-XML-file-to-SAML-Configuration-of/m-p/640669#M2191</link>
      <description>&lt;P&gt;I am having the same issue and I just opened a case with Splunk.&amp;nbsp; &amp;nbsp;I will respond later today when i find out.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 17:54:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-re-import-the-metadata-XML-file-to-SAML-Configuration-of/m-p/640669#M2191</guid>
      <dc:creator>bobmccoy</dc:creator>
      <dc:date>2023-04-19T17:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to re-import the metadata XML file to SAML Configuration of Splunk Cloud?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-re-import-the-metadata-XML-file-to-SAML-Configuration-of/m-p/660975#M2573</link>
      <description>&lt;P&gt;Was this ever resolved without the need of Splunk Support?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 07:53:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-re-import-the-metadata-XML-file-to-SAML-Configuration-of/m-p/660975#M2573</guid>
      <dc:creator>nickrob1971</dc:creator>
      <dc:date>2023-10-17T07:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to re-import the metadata XML file to SAML Configuration of Splunk Cloud?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-re-import-the-metadata-XML-file-to-SAML-Configuration-of/m-p/743251#M3696</link>
      <description>&lt;P&gt;In this situation, it could mean one of two things.&amp;nbsp; The first is that you're trying to use a cert chain and there is already a single cert in idpCert.pem.&amp;nbsp; Some IdP's like Ping require you to remove that idpCert.pem.&amp;nbsp; However, the more likely case here is that you have multiple single certs attached to your IdP metadata.xml file.&lt;/P&gt;&lt;P&gt;Some IdP's such as ADFS and Azure (Entra) allow for Primary and Secondary IdP certs, which allow for seamless transition from expiring to new certs.&lt;/P&gt;&lt;P&gt;However, Splunk does NOT accept two single certs in one metadata.xml file.&amp;nbsp; Hence, your solution here is as below:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; On the IdP, replace the expiring cert with the new cert&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Disable secondary cert option&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Download the new metadata.xml file&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; Upload the IdP metadata.xml file to Splunk UI &amp;gt; Save&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;footnote:&amp;nbsp; Splunk DOES accept cert chains, but that has to be manually uploaded and in the correct order as per KB below:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Deployment-Architecture/Problem-with-SAML-cert-quot-ERROR-UiSAML-Verification-of-SAML/m-p/322376#M12073" target="_blank"&gt;https://community.splunk.com/t5/Deployment-Architecture/Problem-with-SAML-cert-quot-ERROR-UiSAML-Verification-of-SAML/m-p/322376#M12073&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 14:14:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-re-import-the-metadata-XML-file-to-SAML-Configuration-of/m-p/743251#M3696</guid>
      <dc:creator>nsanzar_splunk</dc:creator>
      <dc:date>2025-04-02T14:14:13Z</dc:date>
    </item>
  </channel>
</rss>

