When attempting to log in to Anypoint Platform using SAML Single Sign-On (SSO), you may observe the following error message:
"Unauthorized: Invalid signature."
This issue affects all users attempting to authenticate via SSO.
Anypoint Platform has deprecated support for SAML certificates signed with the SHA-1 hashing algorithm. If your Identity Provider (IdP) is configured to sign SAML assertions using SHA-1, Anypoint Platform will reject the assertion, resulting in an "Invalid signature" error during the login process. Anypoint Platform requires SAML assertions to be signed with SHA-256 or a stronger hashing algorithm.
To resolve this issue, update your Identity Provider's SAML signing certificate to use SHA-256 or a stronger algorithm, and then update the corresponding configuration in Anypoint Platform.
* Access your Identity Provider's configuration for the Anypoint Platform SAML application.
* Locate the setting for the SAML signing algorithm. Confirm if it is currently set to SHA-1.
* *Note:* The exact steps vary depending on your IdP (e.g., Okta, Azure AD, Salesforce, ADFS). Consult your IdP's documentation for specific instructions.
* Generate a new SAML signing certificate within your Identity Provider that uses the SHA-256 hashing algorithm.
* Configure your IdP to use this new SHA-256 certificate for signing SAML assertions for Anypoint Platform.
* Download the new SHA-256 certificate (typically in .cer or .pem format).
* Log in to Anypoint Platform as an Organization Administrator.
* Navigate to Access Management > Identity Providers.
* Select your existing SAML 2.0 configuration.
* Locate the section for the Identity Provider Certificate.
* Upload the newly generated SHA-256 certificate from your IdP.
* Save the changes to your Anypoint Platform SAML configuration.
For detailed instructions on configuring SAML SSO in Anypoint Platform, refer to the official documentation: [Configure SAML 2.0](https://docs.mulesoft.com/access-management/conf-saml-sso)
005389638

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.