<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Update SAML IDP metadata in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240180#M46598</link>
    <description>&lt;P&gt;Hi Gianni,&lt;/P&gt;
&lt;P&gt;Please keep us updated. This thread will relevant for others too.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
    <pubDate>Sun, 02 Feb 2025 14:55:38 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2025-02-02T14:55:38Z</dc:date>
    <item>
      <title>Update SAML IDP metadata</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240163#M46592</link>
      <description>&lt;P&gt;Hello dear ChechMates, in a few days the IDP certificate with which we authenticate SAML VPN Mobile and Remote Access accesses expires.&lt;/P&gt;&lt;P&gt;Trying to update the metadata in the Identity Provider object I get this error and am unable to proceed.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;Gianni.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 15:00:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240163#M46592</guid>
      <dc:creator>GianniPapetti</dc:creator>
      <dc:date>2025-01-31T15:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Update SAML IDP metadata</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240175#M46595</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/48470"&gt;@GianniPapetti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I remember correctly, but I can't recall it for 100% sure. You need to remove the the object from the "Authenticaton" here. Remove the Identity Provider object.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-01-31 16_42_29-10.36.1.10-R81.20-SmartConsole.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29499iEBE99F1C4B80E242/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2025-01-31 16_42_29-10.36.1.10-R81.20-SmartConsole.png" alt="2025-01-31 16_42_29-10.36.1.10-R81.20-SmartConsole.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The "where use" does not show the exact place.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Keep in mind:&lt;/STRONG&gt; During this change the authentication won't work&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 15:45:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240175#M46595</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-31T15:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: Update SAML IDP metadata</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240178#M46596</link>
      <description>&lt;P&gt;Think you are right.&lt;/P&gt;&lt;P&gt;We have both Mobile and Remote access via SAML Auth; will try with Mobile first cause less used.&lt;/P&gt;&lt;P&gt;Thanks a lot,&lt;/P&gt;&lt;P&gt;Gianni.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 16:04:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240178#M46596</guid>
      <dc:creator>GianniPapetti</dc:creator>
      <dc:date>2025-01-31T16:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: Update SAML IDP metadata</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240180#M46598</link>
      <description>&lt;P&gt;Hi Gianni,&lt;/P&gt;
&lt;P&gt;Please keep us updated. This thread will relevant for others too.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2025 14:55:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240180#M46598</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-02-02T14:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Update SAML IDP metadata</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240222#M46602</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;just added a new IDP with updated medatata for example 2025_IdP&lt;/P&gt;&lt;P&gt;I have access to the IdP side so it was super easy ti update ACS and EntityID parameters after creation&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2025 14:24:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240222#M46602</guid>
      <dc:creator>GianniPapetti</dc:creator>
      <dc:date>2025-02-02T14:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: Update SAML IDP metadata</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240250#M46605</link>
      <description>&lt;P&gt;The way&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp; wrote is what i did some weeks ago, and it worked.&lt;/P&gt;&lt;P&gt;Just remove the idp from the login options settings, renew metadata xml and reassign it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 08:54:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/240250#M46605</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2025-02-03T08:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: Update SAML IDP metadata</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/267477#M52865</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we tried the same thing yesterday and today but we run into an issue.&lt;/P&gt;&lt;P&gt;Our certificate is about to expire tomorrow so we created a new one in EntraID, created a new IDP object on the firewall with the new metadata and changed the object in the authentication settings.&lt;/P&gt;&lt;P&gt;However, when we activate the new certificate in EntraID the login fails with a HTTP 500 on the ACS/Reply URL. If we reactivate the old certificate login works again even though the new IDP object is used in the firewall.&lt;/P&gt;&lt;P&gt;Any idea how this is possible?&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Dominik&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2026 14:17:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/267477#M52865</guid>
      <dc:creator>Dominik_M</dc:creator>
      <dc:date>2026-01-15T14:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: Update SAML IDP metadata</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/267488#M52871</link>
      <description>&lt;P&gt;When creating new IDP objects, new links (entity id and Reply url) are different, so your IDP cannot identify the authentication request, as entity ID is wrong.&lt;/P&gt;&lt;P&gt;So either create a new IDP and reconfigure on IDPs side the application to trust / use the Entity ID / Reply URL or edit the existing, like below - would prefer the first, if you have access to IDP &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will have to unset the identity provider object from authentication configuration (login option) (Make screenshots, for reverting the configuration when change is done), than do your changes (import new certificate/metadata.xml) and relink the object to authentication configuration.&lt;/P&gt;&lt;P&gt;Once the new cert is imported, you can revert the unset/unlinking above and reset the authentication via the IDP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During the configuration, do NOT Publish or install Policy. When config is done, install policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2026 14:46:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/267488#M52871</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2026-01-15T14:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Update SAML IDP metadata</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/267504#M52877</link>
      <description>&lt;P&gt;We had the same issue and had to remove the old certificate first in EntraID before generating the metadata.xml.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2026 16:52:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/267504#M52877</guid>
      <dc:creator>greg42</dc:creator>
      <dc:date>2026-01-15T16:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Update SAML IDP metadata</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/267560#M52903</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;we solved it yesterday together with TAC and I want to share the things that helped us.&lt;/P&gt;&lt;P&gt;After analyzing /opt/CPVPNPortal/logs/error_log we saw an error in the latest entries pointing to&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk176183" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk176183&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This was most likely caused since we had created new Identity Provider objects while debugging this issue ourselves.&lt;BR /&gt;Even though they weren't all used in the active configuration this caused some issues with the validation.&lt;/P&gt;&lt;P&gt;After removing all but one object the error in&amp;nbsp;/opt/CPVPNPortal/logs/error_log changed and we still had the HTTP Error 500.&lt;BR /&gt;Support pointed us to&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk178025" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk178025&lt;/A&gt;&amp;nbsp;with scenario 4.&lt;/P&gt;&lt;P&gt;We checked the metadata file we got from EntraID and figured that there were multiple certificates.&lt;BR /&gt;Instead of editing the metadata file itself, we decided to switch to the manual configuration. I'm sure editing the metadata file or maybe removing the old certificate in EntraID and generating a new metadata file would both also work.&lt;/P&gt;&lt;P&gt;What we did was we set authentication back to username and password, removed the old object and created a new one.&lt;BR /&gt;Then we updated ACS and Identifier on EntraID side before entering the Identifier and Login URL into the object on the firewall. Last step was adding the certificate for which we went with the base64 version we could download from EntraID after verifying that only one certificate was present in the file.&lt;/P&gt;&lt;P&gt;After publishing and installing the policy the VPN authentication worked again.&lt;/P&gt;&lt;P&gt;I'm pretty sure that the instructions that&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1663"&gt;@Nüüül&lt;/a&gt;&amp;nbsp;wrote would've worked if we hadn't created so many new objects in our debugging process and if we had either removed the old certificate first in EntraID or edited the metadata file to ensure only one certificate was present.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Dominik&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 07:59:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Update-SAML-IDP-metadata/m-p/267560#M52903</guid>
      <dc:creator>Dominik_M</dc:creator>
      <dc:date>2026-01-16T07:59:52Z</dc:date>
    </item>
  </channel>
</rss>

