-
Type:
Suggestion
-
Resolution: Won't Fix
-
Component/s: IdP SSO - User Login
-
4
Problem Definition
When the X.509 SAML public certificate expires:
Users receive an error message this is too generic
There is not way for an organization admin to proactively know that this certificate will soon expire or is already expired.
Suggested Solution
Capture and display the status of the certificate if it is about to expire or is already expired to organization admins and provide a more specific error message to users.
Workaround
Manually check that your X.509 SAML public certificate is expired.
When a public certificate used for SAML is expired, the error that users get is too generic, mentioning only that "there seems to be an issue with the SAML public key.
In the case of certificate expiry, we should capture this event and provide a more specific error message, informing the user about the expiry of the certificate.
- mentioned in
-
Page Loading...