BCFKS Keystore unable to recover private key (saml2sp): Error finalising cipher data: mac check in CCM failedIssue <!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } Customer reports instance successfully configured with Multi-Provider SSO features using their own IDP. Login with SSO works successfully. Logout also works but generates the following error / message: Logout successfulYou have been successfully logged out of our service. However, we could not verify that your session with the Identity Provider (IdP) was terminated. If necessary please log out directly from your Identity Provider. Symptoms<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } Application node logs will show errors such as: 2025-12-11 13:23:35 (354) Default-thread-27 E72A500534F9B6105F4257BE08C3F370 txid=fd2b1cc134f9 LocalhostTransactionLogger *** Start #98216 /logout.do, type: form, user: <user ID>2025-12-11 13:23:35 (354) Default-thread-27 E72A500534F9B6105F4257BE08C3F370 txid=fd2b1cc134f9 RedirectTransaction User: <user ID> logged out 2025-12-11 13:23:35 (357) Default-thread-27 E72A500534F9B6105F4257BE08C3F370 txid=fd2b1cc134f9 SecureUserCookie Deleting user: <user ID> token: CAnvmRUS5dH2bJ/rasd3N3DjwFUcasrIkrgQAEVMi18=2025-12-11 13:23:35 (380) Default-thread-27 E72A500534F9B6105F4257BE08C3F370 txid=fd2b1cc134f9 SAMLRequestIDGenerator SAMLRequestIDGenerator: received saml login request, remote address:<IP>, Referer:https://<instance-name>/now/nav/ui/classic/params/ target/syslog_list.do%3Fsysparm_userpref_module%3Dab0b7690c0a8016400bdb8598ce01adf%26sysparm_query%3Dsys_createdL_onONToday%2540javascript%253Ags.daysAgoStart%25280%2529%2540javascript%253Ags. daysAgoEnd%25280%2529%255EEQ%26sysparm_order%3Dsys_created_on%26sysparm_order_direction%3Ddesc%26sysparm_clear_stack%3Dtrue, session id:5EC327F98DC88447539F16A9E14BCF402025-12-11 13:23:35 (380) Default-thread-27 E72A500534F9B6105F4257BE08C3F370 txid=fd2b1cc134f9 SAMLRequestIDGenerator SAMLRequestIDGenerator: generated saml request id:SNCbacas7cfc4452aed664fdd682025-12-11 13:23:35 (463) Default-thread-27 E72A500534F9B6105F4257BE08C3F370 txid=fd2b1cc134f9 SysLog *** ERROR *** SAML2: BCFKS KeyStore unable to recover private key (saml2sp): Error finalising cipher data: mac check in CM failed2025-12-11 13:23:35 (471) Default-thread-27 E72A500534F9B6105F4257BE08C3F370 txid=fd2b1cc134f9 Sessions Session destroyed: E72A500534F9B6105F4257BE08C3F370, <user ID>, created Thu Dec 11 13:19:20 PST 2025, interactive: true, maxInactiveInterval: 600s2025-12-11 13:23:35 (474) Default-thread-27 E72A500534F9B6105F4257BE08C3F370 txid=fd2b1cc134f9 LoginHistoryServiceImpl *** WARNING *** Identity Center:Unable to invalidate web login activity as no active session found. Release<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } All Releases Cause<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } The password for the instance's x509 Keystore record responsible for Encryption & Signing has an incorrect password configured. Resolution<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } Go to the instance's IDP record in question. Make a backup of it by using the Export->XML (this record) action. Do this in case you need to revert/backout/restore.Go to the "Encryption and Signing" tabre-enter the correct "Signing key password" field value -- Note if using our OOB Keystores such as: "SAML 2.0 Keystore_Key2048_SHA256_FIPS" "SAML 2.0 Keystore_Key2048_SHA256_FIPS_Signing" "SAML 2.0 Keystore_Key2048_SHA256_FIPS_Encryption" The password value is "saml2sp" -- otherwise if customer is using their own self-provisioned Keystore, the password will be unknown to ServiceNow and they will need to ask their Public Key Infrastructure (PKI) team/admin to provide the password.Save the IDP record