Replacing a Service Provider (SP) signing certificate for a custom Security Assertion Markup Language (SAML) application requires uploading the new certificate within the application settings. Administrators can accomplish this by navigating to the SAML settings in the Okta Admin Console and uploading the new certificate file.
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Custom Security Assertion Markup Language (SAML) applications with a Service Provider (SP) Signing Certificate
- Single Sign-On (SSO)
How is a Service Provider signing certificate replaced in Okta?
Review the video or navigate to the application settings in the Okta Admin Console, access the advanced SAML settings, and upload the new certificate file.
- In the Okta Admin Console, select Applications.
- Select the application intended for certificate replacement.
- Select the General tab.
- Scroll to SAML Settings and select Edit.
- Select Next, and then select Show Advanced Settings.
- Locate the Signature Certificate file name.
- Select Browse files....
- Select the
.crtfile to upload, and select Upload Certificate. - Select Next.
- Select Finish.
