CIsco ISE - Error when opening STS SAML Identity provider
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-26-2021 05:51 AM
Has anyone came across the following error when trying to upload a XML config to the STS profile:
‘Signing certificate validation failed, error: The IdP signing certificate expired. Reconfigure SAML Identity Provider with updated metadata’
Cisco ISE 2.7
Thanks
- Labels:
-
Identity Services Engine (ISE)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-27-2021 03:44 PM
This means the metadata XML file contains a field for the signing certificate of your STS SAML IdP and that certificate has expired according to the system time of your ISE deployment. Please check the XML file. Likely you would be able to extract the certificate and verify its expiration date. Check your IdP and renew/update its signing certificate before re-exporting the metadata file.
