<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z000079kIXTCA2Okta Classic EngineSingle Sign-OnAnswered2024-04-15T10:48:28.000Z2021-09-08T18:34:21.000Z2021-09-16T19:55:35.000Z

r2w3u (r2w3u) asked a question.

Okta SAML signing certificate rotation

We are using the 'out of the box' SAML signing certificate for Okta applications, which appears to be a global certificate for all applications, self-signed by Okta. In our case it is somewhat long-lived (10 years).

 

As the number of applications grows in our org, I am concerned about the work that will be required when we eventually have to rotate this certificate. I am curious how other Okta customers are managing this problem? Are other customers using custom certificates for each application? If so, how are they rotating them when necessary, since they also have to be changed on the application side?

 

On the Okta side, what is the process for rotating the SAML certificate when it expires? Is a new certificate provided in advance with overlap so customers can migrate to the new one?


This question is closed.
Loading
Okta SAML signing certificate rotation