Single Sign-On

Set up Single Sign-On between Zivver and your identity provider.

Resolving SAML Signing Errors After Renewing Certificates for Entra ID SSO

Introduction

When using Single Sign-On (SSO) with Azure/Entra ID, you may encounter the error:

"error": "SAML response was not properly signed. Make sure to sign at least the SAML response or the assertion(s)."

This typically happens after renewing the SAML signing certificate in Entra ID. The underlying cause is a known issue for every identity provider, not just Entra ID — see SSO login fails after renewing your identity provider’s SAML certificate for the cause and the full resolution.

Get the new certificate and metadata from Entra ID

Follow these steps to activate the new certificate in Entra ID and export its metadata. Then continue with step 2 of the general resolution to apply it in Zivver.

  1. Log in to the Azure admin center.
  2. Search for Enterprise applications and select it.
  3. In the Enterprise applications page, search for Zivver and select the SSO application.
  4. Under Manage, select Single sign-on.
  5. In the SAML Certificates card, click the Edit button.
  6. Create or import a new certificate.
  7. Make the new certificate Active.
  8. Open the XML metadata from the Metadata URL in a new tab.
  9. Save the XML metadata as an .xml file on your computer.
  10. Open the .xml file in a plain text editor (e.g., Notepad, VSCode, or Notepad++).
  11. Copy the entire content of the XML file to your clipboard.