The public-private key pair that is used for signatures in your IdP is rotated. However, the metadata of your IdP in Alibaba Cloud is not updated. | Update the metadata of your IdP in Alibaba Cloud. You can download the latest metadata file from your IdP, and then upload the metadata file to Alibaba Cloud. |
The public-private key pair that is used for signatures in your IdP is rotated, and the metadata of your IdP in Alibaba Cloud is updated. During the rotation, the original private key may still be used in your IdP. The metadata of your IdP in Alibaba Cloud contains only the new public key. | We recommend that you specify both the original public key and the new public key in the metadata of your IdP. - Create a certificate. Do not disable or delete the original certificate.
- Download the new metadata file and check whether the original public key and the new public key are included in the metadata file.
- For some IdPs, such as Azure AD, the original certificate and new certificate are included in the new metadata file.
- If the new metadata file does not contain the original public key and the new public key, you must manually add the original certificate and new certificate to the new metadata file. You can download the original metadata file from the SSO settings in the CloudSSO console and copy information about the
X509Certificate element, which is information about the original certificate. Add the copied information to the KeyDescriptor element of the new metadata file and save the modification. - Upload the new metadata file to the SSO settings in the CloudSSO console.
- Enable the new certificate and disable the original certificate in the SSO settings of your IdP.
|
The metadata file failed to be uploaded because the size of the metadata file is excessively large. | Wait until the upload is complete. After the upload is complete, download the uploaded metadata file to check whether the metadata file is uploaded. |