If you or your learners see an Internal Server Error when opening a link to the SoSafe E-Learning platform, this article helps you find out what is causing it and what to do next.
In most cases, this error means that the certificate behind your organization's Single Sign-on (SSO) connection has expired. Fixing it requires admin access to your identity provider and to the SoSafe Manager. If you do not have that access, send your IT department a link to this article. Training progress won’t be affected.
Are you seeing this error?
The error appears after selecting a link in a reminder or invitation email, or when signing in to the E-Learning platform. The page does not load and shows a message like this:
{"title":"Internal Server Error","status":500,"reference":"00000000-0000-0000-0000-000000000000","randomUUID":"00000000-0000-0000-0000-000000000000"}
The reference and randomUUID values are different for every error, so yours will not match the example above. Two things confirm you are in the right place:
-
The address bar shows a URL ending in /auth/saml/consume
-
Your organization signs in to SoSafe using SSO
What causes this
Your organization signs in to SoSafe using an SSO connection based on SAML. That connection relies on a signing certificate, and the certificate expires on a schedule set by your identity provider. Once it expires, sign-in stops working and learners see the error above.
Some identity providers warn you ahead of the expiry date. Microsoft Entra ID, for example, sends a notification email with the subject "Please renew your application certificate".
If you are an admin
You have 2 options. We recommend migrating to Enterprise SSO, because it removes the recurring certificate renewal and puts the configuration in your own hands.
Migrate to Enterprise SSO
Enterprise SSO is our current SSO solution, powered by Auth0. You set it up yourself in the SoSafe Manager through a guided wizard, and you can change your configuration there later without contacting support. It also does not use a SAML signing certificate that has to be renewed with us.
Migrating is easy and should take less than hour: Migration to Auth0 SSO
Request a certificate renewal
If you cannot migrate right now, SoSafe support can update your SAML certificate for you. Reach out to your point of contact and provide your new certificate.
Please note that this restores sign-in but does not prevent the problem from returning. The replacement certificate will also expire, and every renewal has to go through support, which means your learners will be locked out again each time it lapses.
Frequently asked questions
Will migrating affect my learners' training progress?
No. Training progress and analytics are not affected, as long as the email addresses of your users stay the same.
Can I migrate while a campaign is running?
Yes. The migration only changes how your users sign in. It does not touch campaigns, training data, or user provisioning.
How long will my learners be unable to sign in?
Usually less than 1 hour. This covers the time between disconnecting the legacy connection and completing the new one. After you enable the new connection, allow up to 10 minutes for all data to synchronize.
Do I need to contact SoSafe support to migrate?
No. Both the migration and the new setup are self-service, and so is any configuration change you make afterwards.
Can I go back to the legacy setup after migrating?
No. Disconnecting the legacy connection is irreversible. Once you start, complete the new setup to restore sign-in.