This article describes how to configure multiple active signing certificates for a single external Security Assertion Markup Language (SAML) identity provider (IdP). This feature allows for seamless certificate rotation with zero downtime by supporting up to two active certificates per IdP connection, reducing the risk of authentication failures during certificate swaps.
- SAML 2.0 External Identity Providers
- Certificates
- Early Access (EA) features
To upload and manage multiple signing certificates for a SAML IdP, follow these steps:
- In the Admin Console, go to Security > Identity Providers.
- Locate the specific SAML IdP and select Edit.
- Navigate to the SAML Protocol Settings section.
- To add a second certificate, navigate to IdP Signature Certificate > Additional certificate (optional), select Browse files.
- Upload the new certificate.
- Select Save.
