Generate a Two-Year SAML Signing Certificate in Okta
Last Updated:
Overview
Generating a two-year Security Assertion Markup Language (SAML) signing certificate using the Okta Postman API collection serves as an alternative to the standard ten-year SAML signing certificate. The process involves running specific API requests in Postman to generate the certificate, then activating it in the Okta Admin Console.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Security Assertion Markup Language (SAML)
- Signing Certificate
Solution
What are the prerequisites for generating a SAML signing certificate?
Prepare the environment by configuring Postman for Okta and importing the necessary application collections.
What steps generate and activate a two-year SAML signing certificate?
Generate the certificate using the Okta Postman Apps collection, activate it in the Okta Admin Console, and upload it to the service provider by following these steps.
- Run the List Apps request from the Okta Postman Apps collection.
- Navigate to Apps > Feature Operations > Get List Apps.
- Use the following call:
GET {{url}}/api/v1/apps
NOTE: Find the AppId in the response body and record it, or collect the AppId by accessing the application in the Okta Admin Console and copying it from the browser URL.
- Run the Generate Certificate request from the Okta Postman Apps collection.
- Navigate to Apps > Certificate Operations > Post Generate Certificate.
- Use the following API call, inserting the recorded
AppIdin<appId>and the desired number of years in<validityYears>.POST {{url}}/api/v1/apps/{{appId}}/credentials/keys/generate?validityYears={{validityYears}}
- Select Send.
- Navigate to the Okta Admin Console, select the specific application, choose the Sign On tab, and activate the new SAML signing certificate.
- Upload the new SAML signing certificate to the application or Service Provider (SP) using one of the following methods.
- View the SAML Setup Instructions under the Sign On tab and download the certificate.
- Provide the Identity Provider (IdP) metadata to the SP and save it as an XML file.
- Download the new certificate from the Okta Admin Console by navigating to SAML Signing Certificates, selecting Actions, choosing Download Certificate or View IdP metadata, and saving it as an XML file.
NOTE: If the "errorSummary": "Validity years out of range. It should be 2 - 10 years" error is encountered, keep in mind this is hardcoded.
