SAML Integrations Not Working after Signing Key Rotation
Last Updated:
Overview
After rotating signing keys, SAML integrations were not working even though the previous signing key had not yet been revoked.
Symptoms
Logins through SAML connections either with Auth0 as the SP or IdP will fail after signing key rotation even if the previous key has not been revoked.
Applies To
- SAML
- Key Rotation
Cause
Solution
- Coordinate a time with your partners to rotate the signing key
- Immediately after you rotate the signing key, download the new tenant certificate from:
https://tenant.{us/eu/au}.auth0.com/pem
- Provide the certificate to your partners. If your partner is a SAML SP they will use the certificate for verify SAML responses from Auth0, if your partner is a SAML IdP they will use the certificate to verify SAML requests from Auth0.