Splunk Enterprise

Verification of SAML assertion using the IDP's certificate provided failed

tlam_splunk
Splunk Employee
Splunk Employee

Find that the portal SSO is not working. It returns the error of the verification of the signature in the certificate idpCert.pem after renewal.
It's because in ADFS has ONE certificate originally , but the certificate will be expired next week, so one month before, ADFS will have one more certificate generated automatically and put it as secondary. Then two weeks before expiry, it will change the new certificate as the Primary and the old certificate as the secondary automatically. Later, the 2nd one will be removed from ADFS. That’s the way working in AFDS. that’s we see TWO certificates now.

We try to regenerate the metadata from the ADFS like the originally configuration
(simiar steps as http://blogs.splunk.com/2016/09/14/configuring-microsofts-adfs-splunk-cloud/)
And try to import the new xml (federationmetadata.xml) into the SAML configuration in the Splunk
It encounters the error “There are multiple cert,idepCertPath,idpCert.pem, must be directory"
Try to remove the idpCert.pem in the ./etc/auth/idpCerts/idpCert.pem.
And then re-import the metadata again but it encounters the “Sever Error”

Any way to fix it.

Tags (1)
0 Karma

tlam_splunk
Splunk Employee
Splunk Employee

Find a way to fix it.


Update the idpCert.pem file after the ADFS certificate is updated

  • Generation of the federationmedata.xml from ADFS
  • Open the xml file by the xml viewer
  • Find the X509Data -> X509Certificate
  • Backup the idpCert.pem and create a new one

-----BEGIN CERTIFICATE-----
< content of the X509 Certificate>
-----END CERTIFICATE-----


0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...