<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Troubleshooting Error "Digital signature in the SAML response did not validate with the Identity Provider's certificate"
Single Sign-On
Okta Classic Engine
Okta Identity Engine
Overview

With Entra ID as the Identity Provider (IdP) and Okta as the Service Provider (SP), the following errors may be seen when attempting to sign into Okta:
 

Authenticate user via IDP FAILURE: Unable to validate incoming SAML Assertion
 

Error Message

 

The digital signature in the SAML response did not validate with the Identity Provider's certificate

 

Error Message

 

 

Applies To
  • Entra ID
  • Single Sign-On (SSO)
  • Certificate error
Cause

The certificate uploaded to Okta from Entra ID is either expired or incorrect and does not match the current, valid certificate downloaded from Entra ID.

Solution
  1. Download the certificate from Entra ID by navigating to Microsoft Entra admin center > Applications > Enterprise applications > [Enterprise App Name] > Single sign-on > SAML Certificates > Certificate (Base64).

Download certificate

  1. Delete the certificate in the Okta Admin Console by navigating to Security > Identity Providers > select the [Name of IdP] > click Actions dropdown menu > select Configure Identity Provider > click Edit >  click X in the IdP Signature Certificate section.IdP Signature Certificate section   

  2. Upload the new certificate downloaded from Entra ID.

Upload the new certificate 

Loading
Troubleshooting Error "Digital signature in the SAML response did not validate with the Identity Provider's certificate"