Unable to configure SAML using OneLogin -Uploaded Certificate is Invalid

Unable to configure SAML using OneLogin -Uploaded Certificate is Invalid

Upon configuring SAML, if you come across the below errors:

Uploaded Certificate is Invalid (Happens with .PEM cert generated in OneLogin)
failed to update IdP details. Check logs for details

Verify the below trace in the Logs:
java.security.cert.CertificateParsingException: java.io.IOException: Duplicate extensions not allowed|
at sun.security.x509.X509CertInfo.<init>(X509CertInfo.java:169)|
at sun.security.x509.X509CertImpl.parse(X509CertImpl.java:1804)|
  at sun.security.x509.X509CertImpl.<init>(X509CertImpl.java:195)|
  at sun.security.provider.X509Factory.engineGenerateCertificate(X509Factory.java:102)|
  at java.security.cert.CertificateFactory.generateCertificate(CertificateFactory.java:339)| 

1. Create a new Certificate in OneLogin:

 

2. Ensure the “set CA Flag in Basic Constraints extension to “true” and keyCertSign bit for KeyUsage” is not enabled. 

3. Edit the One Login configuration to use this new cert generated
4. Download the der file.

5. Try with the .der file