SAP Knowledge Base Article - Public

3110316 - Invalid Assertion Consumer Service URL causes SHA2 migration failure


  • SAP SuccessFactors announced in 2H 2021 that new Assertion Consumer Service entries use the SHA-256 signing certificate by default
  • If there is an invalid Assertion Consumer Service URL configured for Learning integration with the HXM Platform, the current HXM Platform to Learning integration is not properly set up
  • The Learning upgrader will not upgrade from SHA-1 to SHA-256 for that ACS URL
  • As a result, the user will not be able to access Learning from the HXM Platform


  • SAP SuccessFactors HXM Suite
  • SAP SuccessFactors Learning Management System


Product Engineering is working on a solution under LRN-122454


This issue can be resolved by contacting support to manually enable SHA-256 for the ACS URL. 

See Also

New Assertion Consumer Service Entries Use the SHA-256 Signing Certificate by Default


KI2111, LRN-122454, SHA2, SHA-1, SHA-256, migration, integration, invalid acsURLs, failed, fail, failure , KBA , LOD-SF-LMS-ADM , System Admin, Global Variables, References , Known Error


SAP SuccessFactors HXM Suite 2111 ; SAP SuccessFactors Learning all versions