Loading
시스템 관리자에 대한 피싱 방지 MFA 및 전 직원사용자 MFA 적용 안내 더 많이 읽기

Anypoint Platform Login Fails with 'Unauthorized: Invalid signature' During SAML SSO

게시 일자: Jul 22, 2026
상세 설명

When attempting to log in to Anypoint Platform using SAML Single Sign-On (SSO), you may observe the following error message:

"Unauthorized: Invalid signature."

This issue affects all users attempting to authenticate via SSO.

CAUSE

Anypoint Platform has deprecated support for SAML certificates signed with the SHA-1 hashing algorithm. If your Identity Provider (IdP) is configured to sign SAML assertions using SHA-1, Anypoint Platform will reject the assertion, resulting in an "Invalid signature" error during the login process. Anypoint Platform requires SAML assertions to be signed with SHA-256 or a stronger hashing algorithm.

 

솔루션

To resolve this issue, update your Identity Provider's SAML signing certificate to use SHA-256 or a stronger algorithm, and then update the corresponding configuration in Anypoint Platform.

 
1. Verify your IdP's SAML Signing Algorithm:

* Access your Identity Provider's configuration for the Anypoint Platform SAML application.

* Locate the setting for the SAML signing algorithm. Confirm if it is currently set to SHA-1.

* *Note:* The exact steps vary depending on your IdP (e.g., Okta, Azure AD, Salesforce, ADFS). Consult your IdP's documentation for specific instructions.

 
2. Update the SAML Signing Certificate in your IdP:

* Generate a new SAML signing certificate within your Identity Provider that uses the SHA-256 hashing algorithm.

* Configure your IdP to use this new SHA-256 certificate for signing SAML assertions for Anypoint Platform.

* Download the new SHA-256 certificate (typically in .cer or .pem format).

 
3. Update Anypoint Platform SAML Configuration:

* Log in to Anypoint Platform as an Organization Administrator.

* Navigate to Access Management > Identity Providers.

* Select your existing SAML 2.0 configuration.

* Locate the section for the Identity Provider Certificate.

* Upload the newly generated SHA-256 certificate from your IdP.

* Save the changes to your Anypoint Platform SAML configuration.

 

For detailed instructions on configuring SAML SSO in Anypoint Platform, refer to the official documentation: [Configure SAML 2.0](https://docs.mulesoft.com/access-management/conf-saml-sso)

Knowledge 기사 번호

005389638

 
로드 중
Salesforce Help | Article