Scenario
Users can still reach the app, but SSO fails immediately after identity provider signing certificate changes.
Recommended Resolution Path
- Compare the certificate metadata loaded in the ERP against the current IdP signing certificate.
- Check whether the app trusts both old and new certificates during rollover.
- Collect a SAML trace or vendor log for exact validation failures.
- Document certificate rollover ownership so app teams are not surprised next cycle.
Technician Notes
Document what changed, what confirmed the fix, and whether the issue points to a broader standards gap worth addressing for the client.
- Log in to post comments