<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Generate a Two-Year SAML Signing Certificate in Okta

Single Sign-On
Okta Classic Engine
Okta Identity Engine

Overview

Generating a two-year Security Assertion Markup Language (SAML) signing certificate using the Okta Postman API collection serves as an alternative to the standard ten-year SAML signing certificate. The process involves running specific API requests in Postman to generate the certificate, then activating it in the Okta Admin Console.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Security Assertion Markup Language (SAML)
  • Signing Certificate

Solution

What are the prerequisites for generating a SAML signing certificate?

Prepare the environment by configuring Postman for Okta and importing the necessary application collections.

 

What steps generate and activate a two-year SAML signing certificate?

Generate the certificate using the Okta Postman Apps collection, activate it in the Okta Admin Console, and upload it to the service provider by following these steps.

  1. Run the List Apps request from the Okta Postman Apps collection.
    1. Navigate to Apps > Feature Operations > Get List Apps.
    2. Use the following call:
      GET {{url}}/api/v1/apps

API Call to get the appid

NOTE: Find the AppId in the response body and record it, or collect the AppId by accessing the application in the Okta Admin Console and copying it from the browser URL.

 

  1. Run the Generate Certificate request from the Okta Postman Apps collection.
    1. Navigate to Apps > Certificate Operations > Post Generate Certificate.
    2. Use the following API call, inserting the recorded AppId in <appId> and the desired number of years in <validityYears>.
      POST {{url}}/api/v1/apps/{{appId}}/credentials/keys/generate?validityYears={{validityYears}} 
  2. Select Send.

Api Call to generate certificate

  1. Navigate to the Okta Admin Console, select the specific application, choose the Sign On tab, and activate the new SAML signing certificate.
  2. Upload the new SAML signing certificate to the application or Service Provider (SP) using one of the following methods.
    1. View the SAML Setup Instructions under the Sign On tab and download the certificate.
    2. Provide the Identity Provider (IdP) metadata to the SP and save it as an XML file.
    3. Download the new certificate from the Okta Admin Console by navigating to SAML Signing Certificates, selecting Actions, choosing Download Certificate or View IdP metadata, and saving it as an XML file.

 

NOTE: If the "errorSummary": "Validity years out of range. It should be 2 - 10 years" error is encountered, keep in mind this is hardcoded.

 

Related References

Loading
Generate a Two-Year SAML Signing Certificate in Okta | Okta Support