<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk SSO Renewal Azure in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-SSO-Renewal-Azure/m-p/753051#M23076</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253494"&gt;@viku7474&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The recommended/documented process for this is to upload the SAML cert using the UI:&lt;/P&gt;&lt;DIV class=""&gt;&lt;OL class=""&gt;&lt;LI&gt;From the system bar, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Settings &amp;gt; Authentication Methods&lt;/SPAN&gt;.&lt;/LI&gt;&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;External&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section of the page that appears, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;SAML&lt;/SPAN&gt;.&lt;/LI&gt;&lt;LI&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Configure Splunk to use SAML&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;link that appears.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;In the&amp;nbsp;&lt;SPAN class=""&gt;SAML configuration&lt;/SPAN&gt;&amp;nbsp;page, under&amp;nbsp;&lt;SPAN class=""&gt;IdP certificate chains&lt;/SPAN&gt;, paste the contents of the IdP certificate chain into the text field.&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Save&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to close the configuration page.&lt;/LI&gt;&lt;LI&gt;In the Authentication Methods page, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Reload authentication configuration&lt;/SPAN&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Please could you try this approach and let me know how you get on? You can find out more info at&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.3/use-saml-as-an-authentication-scheme-for-single-sign-on/refresh-expiring-saml-identity-provider-certificates" target="_blank" rel="noopener"&gt;https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.3/use-saml-as-an-authentication-scheme-for-single-sign-on/refresh-expiring-saml-identity-provider-certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Sat, 13 Sep 2025 18:23:46 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-09-13T18:23:46Z</dc:date>
    <item>
      <title>Splunk SSO Renewal Azure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-SSO-Renewal-Azure/m-p/752959#M23075</link>
      <description>&lt;P&gt;Our Splunk SSO Azure certificate is about to expire, and we need to renew new certificate in Splunk.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have a 3 SHC machine.&lt;BR /&gt;&lt;BR /&gt;I have placed the new IDP Cert inside etc/auth/idpcert/ dir, and clicked on reload authentication configuration.&lt;BR /&gt;&lt;BR /&gt;The certificate did not replicate.&lt;BR /&gt;&lt;BR /&gt;I have placed the new IDP Cert manually on all the 3 SHC's&amp;nbsp;inside etc/auth/idpcert/ dir, and did the rolling restart.&lt;BR /&gt;&lt;BR /&gt;After the restart, somehow it took the old IPD Certificate. (Checked via Openssl Command)&lt;BR /&gt;&lt;BR /&gt;I have taken the backup and moved the old certificate to a different directory but when I manually place the new IDP Cert, and do a restart, it is reflecting with old cert.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Any ways to fix this issue to renew the new cert?&lt;BR /&gt;&lt;BR /&gt;I don't see Metadata XML configured at the first place. So unsure if we need to install metadata XML or IDP Cert.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2025 08:17:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-SSO-Renewal-Azure/m-p/752959#M23075</guid>
      <dc:creator>viku7474</dc:creator>
      <dc:date>2025-09-12T08:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk SSO Renewal Azure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-SSO-Renewal-Azure/m-p/753051#M23076</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253494"&gt;@viku7474&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The recommended/documented process for this is to upload the SAML cert using the UI:&lt;/P&gt;&lt;DIV class=""&gt;&lt;OL class=""&gt;&lt;LI&gt;From the system bar, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Settings &amp;gt; Authentication Methods&lt;/SPAN&gt;.&lt;/LI&gt;&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;External&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section of the page that appears, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;SAML&lt;/SPAN&gt;.&lt;/LI&gt;&lt;LI&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Configure Splunk to use SAML&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;link that appears.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;In the&amp;nbsp;&lt;SPAN class=""&gt;SAML configuration&lt;/SPAN&gt;&amp;nbsp;page, under&amp;nbsp;&lt;SPAN class=""&gt;IdP certificate chains&lt;/SPAN&gt;, paste the contents of the IdP certificate chain into the text field.&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Save&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to close the configuration page.&lt;/LI&gt;&lt;LI&gt;In the Authentication Methods page, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Reload authentication configuration&lt;/SPAN&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Please could you try this approach and let me know how you get on? You can find out more info at&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.3/use-saml-as-an-authentication-scheme-for-single-sign-on/refresh-expiring-saml-identity-provider-certificates" target="_blank" rel="noopener"&gt;https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.3/use-saml-as-an-authentication-scheme-for-single-sign-on/refresh-expiring-saml-identity-provider-certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Sat, 13 Sep 2025 18:23:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-SSO-Renewal-Azure/m-p/753051#M23076</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-09-13T18:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk SSO Renewal Azure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-SSO-Renewal-Azure/m-p/753056#M23077</link>
      <description>&lt;P&gt;Unfortunately, clustered search head environment is known (since at least 8.2) to have issues with certs getting wrongly replicated across the members causing the old certs to persist.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Sep 2025 18:51:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-SSO-Renewal-Azure/m-p/753056#M23077</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-09-13T18:51:57Z</dc:date>
    </item>
  </channel>
</rss>

