IDP Specific

Why do I get an “SSO certificate expired or mismatch” error during WordPress ADFS SSO?

6 views 0

Probable Cause:

The ADFS certificate used to sign/encrypt SSO responses is outdated or does not match the certificate in the miniOrange plugin configuration.

Solution:

  1. In WordPress, open the miniOrange SAML SSO plugin → Identity Provider (ADFS) configuration.
  2. Update the ADFS certificate in the plugin using either method:
    • Recommended: Import/Update the ADFS IDP Metadata in the plugin (this auto-updates the signing certificate), or
    • Manually paste/upload the latest ADFS Token-Signing X.509 certificate in the plugin's X.509 Certificate field.
  3. Save the configuration.
  4. Run Test Configuration to validate the setup and confirm the certificate is correct.

Note: This issue is usually fixed by updating the ADFS signing certificate in the WordPress plugin (SP side), especially after ADFS certificate rollover.

Still need help?

Contact us at samlsupport@xecurify.com

Was this helpful?


Hello there!

Need Help? We are right here!

support