Single Sign-On
Set up Single Sign-On between Zivver and your identity provider.
SSO login fails after renewing your identity provider's SAML certificate
Introduction
After you renew or rotate the SAML signing certificate at your identity provider (IdP), users can no longer log in to Zivver. This can affect the Admin Panel, WebApp, Chrome Extension, Outlook Web Access (OWA), and the Office plugin all at the same time, because these products share the same SSO configuration. You may see errors such as:
"error": "SAML response was not properly signed. Make sure to sign at least the SAML response or the assertion(s)."
or a certificate error, or a blank SSO login panel.
This applies regardless of which identity provider you use, for example Entra ID, AD FS, Okta, or Google Workspace.
Cause
Zivver caches SSO metadata, including the signing certificate, for up to 24 hours instead of fetching it on every login. After you renew the certificate at your identity provider, Zivver keeps validating logins against the old, cached certificate until the cache expires.
Resolution
- At your identity provider, confirm the new certificate is active and export its federation metadata as an XML file.
See your identity provider’s setup guide for where to find this: Entra ID (or the Entra ID certificate renewal guide for the exact steps), AD FS, Okta, Google Workspace. - Log in to the Zivver WebApp.
- Click
Organization Settings.
- Expand
User administration.
- Click Single Sign-on.
- Select Manually.
- Paste the new federation metadata XML into the Identity Provider’s .XML field.
- Click .
This immediately restores login for the Admin Panel, WebApp, Chrome Extension, OWA, and Office plugin, since they all use this one SSO configuration. - Wait at least 24 hours for the old cached metadata to expire.
- Select Automatically again.
- Enter the Metadata URL in the URL field.
- Click .
This makes sure future certificate renewals are picked up automatically.