The Instructure Community will enter a read-only state on November 22, 2025 as we prepare to migrate to our new Community platform in early December. Read our blog post for more info about this change.
All,
Is anyone using ADFS as a back end for SAML sign on? We've recently encountered an issue with signing certificates wherein prior to ADFSs signing certificate expiring, it adds a new certificate as a primary and rotates the current (soon to expire) certificate into secondary.
Our ADFS metadata then contains two signing certificates, but Canvas (and they have confirmed this) can only handle a single certificate for request signing, and merely choose the first one in the metadata. This causes issues as ADFS is now signing with a new certificate, but the old one continues to appear in the metadata for a week or so, and appears first (not that order should ever matter in XML), thus Canvas believes the incoming request to be invalid and refuses to authenticate the user.
If anyone's worked this out yet, or is current;y struggling with the same issue I'd love to hear from you.
Cheers
Jack
We are giving the Canvas Admins area a little bit of love (especially questions that are really, really old) and just want to check in with you. This will also bring this question new attention.
Were you able to find an answer to your question? I am going to go ahead and mark this question as answered because there hasn't been any more activity in a while so I assume that you have the information that you need. If you still have a question about this or if you have information that you would like to share with the community, by all means, please do come back and leave a comment. Also, if this question has been answered by one of the previous replies, please feel free to mark that answer as correct.
Robbie
Robbie,
Alas, no solution was found and no advice given, so we're just going to have to be aware that this doesn't function automatically and intervene next time the certificates rotate.
Cheers
Jack
Hi jack0x539 - Did you find a way to automate the fingerprint update per chance? We had the same issue recently where it updated ahead of schedule leaving users unable to log in.
Many Thanks,
Helen
Helen,
I'm afraid not no, still stuck in the same boat!
Cheers
Jack
Community helpTo interact with Panda Bot, our automated chatbot, you need to sign up or log in:
Sign inTo interact with Panda Bot, our automated chatbot, you need to sign up or log in:
Sign in
This discussion post is outdated and has been archived. Please use the Community question forums and official documentation for the most current and accurate information.