When trying to test the initial setup of AWS, SAML authentication may receive the following error:
Response signature invalid (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken; Request ID: <requestID>). Please try again.
- Amazon Account Federation (formerly Amazon Web Services)
- AWS IAM Identity Center
- Security Assertion Markup Language (SAML)
- From the Okta Admin Console, navigate to the AWS application in question and select the Sign On Tab.
- Right-click on the Identity Provider metadata and save it into the local directory in .xml format (screenshot attached for Amazon Identity Application).
- Log in to the Amazon Web Service Portal.
- In the Configure Provider screen, locate the SAML provider that was previously created.
- Click on the provider and re-upload the metadata from the SAML setup document generated from the AWS application in Okta.
- Validate that users can now access AWS.
