Erreur de connexion SSO (SAML Response signature invalid) et actualisation des métadonnées dans Shibboleth

Anaïs Beauchamp 40 Points de réputation
2026-09-22T11:47:59.4266667+00:00

Bonjour l'équipe de support,

J'essaie de me connecter au portail de l'université via SSO, cependant, j'obtiens l'erreur "SAML Response signature invalid". Les diagnostics révèlent une non-correspondance de clé publique (public key mismatch) sur les métadonnées de la Relying Party. Pourriez-vous s'il vous plaît m'expliquer étape par étape comment forcer l'actualisation (force refresh) des métadonnées dans Shibboleth ?

Cordialement.

Windows pour les entreprises | Windows 365 Entreprise
0 commentaires Aucun commentaire

Réponse acceptée par l’auteur(e) de la question
VPHAN 44,860 Points de réputation Conseiller(ère) indépendant(e)
2026-09-22T12:30:18.8366667+00:00

Hi Anaïs Beauchamp,

you are encountering a "SAML Response signature invalid" error due to a public key mismatch on the Relying Party metadata. This happens when a SAML certificate has been rotated, but the Shibboleth cache has not yet expired, causing the server to attempt signature validation using the old, outdated public key.

To force a metadata refresh in Shibboleth and pull the correct key, you must have administrative access to the backend servers. Depending on whether you manage the central Identity Provider or the portal's Service Provider, execute the corresponding steps below:

Open a terminal session on the IdP server and navigate to the binary directory, typically located at /opt/shibboleth-idp/bin/. Execute the command ./reload-service.sh -id shibboleth.MetadataResolverService. This native script instructs the IdP to instantly flush its cache and pull the updated metadata file without requiring a disruptive restart of the web container. If it's not yet been solved, open a terminal on the portal's web server. You can immediately clear the cache by restarting the Shibboleth service with the command sudo systemctl restart shibd. If you prefer not to restart the service, you can trigger a targeted refresh by accessing the local handler endpoint; navigate to https://localhost/Shibboleth.sso/RefreshMetadata directly from the server.

Hope this answer has brought you some useful information. If it did, please hit “accept answer”. Should you have any questions, feel free to leave a comment.

VPHAN

Cette réponse vous a-t-elle été utile?

1 personne a trouvé cette réponse utile.
0 commentaires Aucun commentaire

0 réponses supplémentaires

Trier par : Plus récent

Votre réponse

Les réponses peuvent être marquées comme « Acceptées » par l’auteur(e) de la question et « Recommandées » par les modérateurs, ce qui aide les utilisateurs à savoir que la réponse a résolu le problème de l’auteur(e).