Update Your Signature Verification Certificate

Prev Next

When your signature verification certificate used to sign the ADFS SAML response does not match what is in the SAML Administration module of your website, you will receive an error, "Login Failed – Cannot validate SAML token." You can fix this error by updating your Signature Verification Certificate in the SAML Administration module of your website using the following steps. If you need any assistance performing these steps, please contact Support.

Who can use this feature?

System Administrator

Instructions

  1. Sign in to your website solution if you have not already

  2. Expand the Modules menu, click the Site Tools tab, and select the SAML Administration option Modules drop-down menu with the Site Tools and SAML Administration options highlighted.

    Note:

    Access to the SAML Administration section requires System Administrator permissions.

  3. Uncheck the Signature Signing and Verification checkbox An unchecked Signature Signing and Verification checkbox under the Signature Signing and Verification section.

  4. Delete the certificate inside the Signature Verification Certificate box so that the field is empty An empty Signature Verification Certificate field.

  5. Scroll back up and click the Save Changes button A green, rectangular Save Changes button to the right of the Main tab at the top of the screen.

  6. In a new tab, navigate to https://[your website domain]/common/admin/rebuildcache.aspx to rebuild your website cache; you should see a blank page An example rebuild site cache URL in the Google Chrome address bar.

  7. Go back to the SAML Administration module tab and check the Signature Signing and Verification checkbox A checked Signature Signing and Verification checkbox under the Signature Signing and Verification section.

  8. Click the Save Changes button A green, rectangular Save Changes button to the right of the Main tab at the top of the screen.

  9. Sign in to the website using ADFS

  10. The new certificate has now automatically populated into the database Example certificate text within the Signature Verification Certificate field.

    Note:

    The new certificate will not appear in the Signature Signing and Verification field until after an app pool recycles your website (which occurs every night). You can check back after this to see the new certificate populated in this field.