Splunk Cloud Platform

How to re-import the metadata XML file to SAML Configuration of Splunk Cloud?

GoliSH
Engager

Hi All,

I need to re-import new XML metaddata to the Splunk Cloud SAML Configuration which is generated for Azure SSO users. The current cert is valid until 19/02/2023. The issue is when I try to import the new xml (federationmetadata.xml) into the SAML configuration in the Splunk
It constantly encounters the error “There are multiple cert,idepCertPath,idpCert.pem, must be directory"
Try to remove the idpCert.pem in the ./etc/auth/idpCerts/idpCert.pem, and shows Server Error.

I don't know how I can find the path ( ./etc/auth/idpCerts/idpCert.pem) in the Splunk cloud as it is not on=premises.

I really need your help as the current valid will expired very soon (19/02/2023)and results in users and admins being locked out of Splunk Cloud.

Any way to fix it.

"""urgent to solve"""

Many thanks, Goli

@tlam_splunk @gcusello 

I would greatly appreciate it if anyone could help me!

 

0 Karma

nickrob1971
Loves-to-Learn Lots

Was this ever resolved without the need of Splunk Support?

0 Karma

bobmccoy
Explorer

I am having the same issue and I just opened a case with Splunk.   I will respond later today when i find out.  

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @GoliSH,

I haven't an answer to your question.

the only hint I have is to open a case to Splunk Support, also because, using Splunk Cloud you (or your customer) have some credits to engage Splunk Professional Services in problems like your.

ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...