Skip to main content

Documentation Portal

How to renew your SAML/SSO certificate?

When you try to log in in TrendMiner but you see the following message on the login page: "Invalid signature in response from identity provider" it is likely that your SAML/SSO certificate is expired.

saml-sso-invalid signature in response from service provider

You can verify this by checking the certificate expiration date in ConfigHub -> Certificates.

To renew the certificate, download a new certificate and federation data xml file from your SAML provider and upload it in TrendMiner. The following procedure documents this in detail for Entra ID (Microsoft Azure):

  1. Download the Base64 certificate and Federation Metadata XML file from Azure

    sso-certificate-metadata.png
  2. Open ConfigHub - Certificates and upload the Certificate under Trusted Certificates

    ConfigHub certificates
  3. Restart the tm-keycloak service in ConfigHub/Edge Manager -> Services for the certificate to show up

    services-blurred.png
  4. In ConfigHub, go to Identity Providers and click on your SAML IdP. Click on options and edit the connection, browse files and upload the new metadata here and hit save

    saml provider details
  5. Right click options again, and download the metadata file from TrendMiner

    saml download metadata
  6. Upload the TrendMiner metadata in Azure

    saml azure upload metadata
  7. Restart the tm-keycloak service in ConfigHub/Edge Manager