A company uses SAML federation with AWS Identity and Access Management (IAM) for SSO. The identity provider’s certificate was rotated, and users now receive the error: “Error: Response Signature Invalid (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken).” A security engineer must fix the immediate issue and prevent recurrence. Which actions should the engineer take? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: During the next rotation, before the current certificate expires, add the new certificate as a secondary on the identity provider, generate updated metadata, and upload it to the existing IAM identity provider. Perform automated or manual cutover when required., Download the updated SAML metadata from the identity provider and upload it to the existing IAM identity provider used by this integration..
Why this is the answer
The error "Response Signature Invalid" indicates that AWS STS cannot validate the signature of the SAML assertion, usually due to an outdated certificate. Downloading the updated SAML metadata from the identity provider and uploading it to the existing IAM identity provider resource will immediately resolve this by providing AWS with the new signing certificate. To prevent recurrence, during the next rotation, the new certificate should be added as a secondary certificate on the identity provider before the current one expires. This allows for updated metadata containing both certificates to be uploaded to the existing IAM identity provider. AWS can then validate assertions signed by either certificate, enabling a seamless transition without downtime. Creating a new IAM identity provider resource for each rotation is unnecessary and adds management overhead.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed