The Validate Signature is enabled in the keycloak SAML settings. Users cannot log in to the client when authenticating through an expired third-party Identity Provider certificate.
Cause
The third-party Identity provider certificate is expired.
Solution
Procedure
Log in to the Keycloak Admin console.
Click SolutionRealm > Identity Provider.
In Identity Providers, select the required provider.
Enable Validate Signature.
Under SAML Settings, in Validating X509 Certificates, delete the expired certificate and copy and paste the new certificate.