Update Your Signature Verification Certificate

Prev Next

When your signature verification certificate used to sign the ADFS SAML response does not match what is in the SAML Administration module of your website, you will receive an error, "Login Failed – Cannot validate SAML token." You can fix this error by updating your Signature Verification Certificate in the SAML Administration module of your website using the following steps. If you need any assistance performing these steps, please contact Support.

Who can use this feature?

System Administrator

Instructions

  1. Sign in to your website solution if you have not already

  2. Expand the Modules menu, click the Site Tools tab, and select the SAML Administration option:The Modules menu expanded, showing the Site Tools tab and with the Saml Administration option highlighted.

    Note:

    Access to the SAML Administration section requires System Administrator permissions.

  3. Uncheck the Signature Signing and Verification checkbox:The Saml Administration screen with the Signature Signing and Verification checkbox unchecked, and highlighted.

  4. Delete the certificate inside the Signature Verification Certificate box so that the field is empty:The Saml Administration screen with the Signature Verification Certificate field highlighted and empty.

  5. Scroll back up and click the Save Changes button:The Saml Administration screen with the Save Changes button highlighted.

  6. In a new tab, navigate to https://[your website domain]/common/admin/rebuildcache.aspx to rebuild your website cache; you should see a blank page:A web browser with the URL displayed for how to rebuild the cache for your CivicPlus website.

  7. Go back to the SAML Administration module tab and check the Signature Signing and Verification checkbox The Saml Administration screen with the Signature Signing and Verification checkbox checked and highlighted.

  8. Click the Save Changes button:The Saml Administration screen with the Save Changes button highlighted.

  9. Sign in to the website using ADFS

  10. The new certificate has now automatically populated into the database:The Saml Administration screen with the Signature Verification Certificate field filled and highlighted.

    Note:

    The new certificate will not appear in the Signature Signing and Verification field until after an app pool recycles your website (which occurs every night). You can check back after this to see the new certificate populated in this field.