Hi Anaïs Beauchamp,
you are encountering a "SAML Response signature invalid" error due to a public key mismatch on the Relying Party metadata. This happens when a SAML certificate has been rotated, but the Shibboleth cache has not yet expired, causing the server to attempt signature validation using the old, outdated public key.
To force a metadata refresh in Shibboleth and pull the correct key, you must have administrative access to the backend servers. Depending on whether you manage the central Identity Provider or the portal's Service Provider, execute the corresponding steps below:
Open a terminal session on the IdP server and navigate to the binary directory, typically located at /opt/shibboleth-idp/bin/. Execute the command ./reload-service.sh -id shibboleth.MetadataResolverService. This native script instructs the IdP to instantly flush its cache and pull the updated metadata file without requiring a disruptive restart of the web container. If it's not yet been solved, open a terminal on the portal's web server. You can immediately clear the cache by restarting the Shibboleth service with the command sudo systemctl restart shibd. If you prefer not to restart the service, you can trigger a targeted refresh by accessing the local handler endpoint; navigate to https://localhost/Shibboleth.sso/RefreshMetadata directly from the server.
Hope this answer has brought you some useful information. If it did, please hit “accept answer”. Should you have any questions, feel free to leave a comment.
VPHAN