Here are some frequent errors that can occur:
INVALID_ISSUER: This means that you have NOT entered the correct Issuer or Entity ID value provided by your Identity Provider. You’ll see in the error message what was the expected value (that you have configured) and what actually found in the SAML Response.
INVALID_AUDIENCE: This means that you have NOT configured Audience URL in your Identity Provider correctly. It must be set to https://base-url-of-your-joomla-site/plugins/authentication/miniorangesaml/ in your Identity Provider.
INVALID_DESTINATION: This means that you have NOT configured Destination URL in your Identity Provider correctly. It must be set to https://base-url-of-your-joomla-site/plugins/authentication/miniorangesaml/saml2/acs.php in your Identity Provider.
INVALID_SIGNATURE: This means that the certificate you provided did not match the certificate found in the SAML Response. Make sure you provide the same certificate that you downloaded from your IdP. If you have your IdP’s Metadata XML file then make sure you provide certificate enclosed in X509 Certificate tag which has an attribute use=’ signing’.
INVALID_CERTIFICATE: This means that the certificate you provided is not in a proper format. Make sure you have copied the entire certificate provided by your IdP. If copied from IdP’s Metadata XML file, make sure that you copied the entire value.