問題文
Users report that single sign-on into the org stopped working this morning. The architect wants to decide quickly whether the problem is in the assertion itself or in the org's configuration. What is the most appropriate first step?
選択肢
- Read the login history, because the error recorded there separates assertion problems from configuration problems.
- Run the assertion validator with an assertion you write by hand, and treat that result as the verdict on the messages the identity provider actually sent this morning.
- Ask the identity provider team to regenerate the signing certificate and upload the new one to the org, and a certificate that has drifted out of sync is the most common cause of a sudden failure and replacing it removes that possibility from the investigation.
- Turn off single sign-on so that users can log in with Salesforce passwords, then investigate later, which restores work for everyone while the cause waits for a quieter hour.