Users cannot log in to the client due to expiry of third-party Identity provider certificate

Last Updated : Jun 10, 2026 |

Condition

The Validate Signature is enabled in the keycloak SAML settings. Users cannot log in to the client when authenticating through an expired third-party Identity Provider certificate.

Cause

The third-party Identity provider certificate is expired.

Solution

Procedure

  1. Log in to the Keycloak Admin console.
  2. Click SolutionRealm > Identity Provider.
  3. In Identity Providers, select the required provider.
  4. Enable Validate Signature.
  5. Under SAML Settings, in Validating X509 Certificates, delete the expired certificate and copy and paste the new certificate.
  6. Click Save.