<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
How to Rotate Signing Certificate for custom SAML Applications
Single Sign-On
Okta Classic Engine
Okta Identity Engine
Overview

This article clarifies whether Okta automatically replaces and activates new certificates for custom Security Assertion Markup Language (SAML) applications before the old certificate expires.

Applies To
  • Custom Security Assertion Markup Language (SAML) Applications

Cause

Administrators receive a notification in the Tasks section of the Okta Admin Console and via email 60 days before the expiration. The administrator needs to renew the signing certificate for each custom SAML application.

Solution

Okta does not automatically replace and activate a new certificate before the old one expires. If the certificate were rotated automatically, the Service Provider (SP) would stop working because the trust with the new signature is not established.

Administrators receive a notification in the Tasks section of the Okta Admin Console and via email 60 days before the expiration. A manual rollover process is necessary to prevent downtime.

  1. In the Okta Admin Console, go to Applications > Applications.

  2. Select the custom SAML application.

  3. Select the Sign On tab.

  4. Scroll to the SAML Signing Certificates section.

  5. 5. Click Generate New Certificate.

    • NOTE: A new certificate is generated with an Inactive status, while the old certificate remains Active.

  6. Download the new certificate or metadata.

  7. Upload the new certificate to the SAML settings of the custom application.

    • NOTE: If the application does not support multiple certificates, perform this step during a scheduled maintenance window.

  8. Return to the SAML Signing Certificates section in Okta.

  9. Locate the new certificate.

  10. Click Actions and select Activate.

SAML Signing Certificates

Loading
How to Rotate Signing Certificate for custom SAML Applications