Allocadia is still configured with the previous IdP signing certificate. Send the new cert to Support and we'll update the SP configuration.
What this answers:
- Why SSO logins fail after a certificate rotation on your IdP
- How to get Allocadia updated with the new certificate
- How to avoid this gap during scheduled rotations
What's happening
When users can't authenticate into Allocadia after a recent certificate rotation on your IdP side (Microsoft Entra ID, Okta, or another SAML 2.0 provider), the cause is almost always that Allocadia is still configured with the previous signing certificate. The IdP signs assertions with the new certificate, Allocadia validates against the old one, the signature check fails, and users either land back at the IdP or at the Allocadia login page.
Symptoms
- Users see "authentication failed" or get returned to a login page after attempting SSO.
- The issue affects all SSO users, not just specific ones (a discriminator from per-user attribute issues).
- The timing matches a recent IdP-side rotation or scheduled key change.
- Some IdPs surface a specific error like "signature verification failed" or "invalid signature" in their logs.
Resolution
Email the new certificate (typically a .cer or .pem file) to Support. We'll update the SP configuration in Allocadia to trust the new certificate.
If your IdP supports rotation windows where both the old and the new certificates can be presented as valid signing certificates simultaneously, that prevents the gap entirely. Allocadia accepts certificates in advance, so you can send the new cert before the cutover and we can stage it.
Prevention for next time
- Notify Support a week ahead of any scheduled IdP certificate rotation. We can configure the new cert in advance, so the cutover is seamless.
- Confirm the rotation date with the team owning your IdP. Many cert rotations are silent and only surface when users complain.
- Check your IdP application configuration once a year for upcoming expirations. Most enterprise IdPs warn 30–60 days in advance.
Related articles
- SSO setup — Microsoft Entra ID
- SSO setup — Okta
- Allocadia "Login As" / Proxy User sends me to a login page
- Does my SSO user need a separate password for the API?
Comments
Please sign in to leave a comment.