<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008giFzvCAEOkta Classic EngineSingle Sign-OnAnswered2026-02-03T09:00:42.000Z2023-01-18T20:00:20.000Z2023-01-20T20:52:01.000Z

si6hv (si6hv) asked a question.

How to add a secondary cert for an Application's SSO / SAML

We have a vendor who's SAML/SSO certificate is going to expire at the end of January. According to the vendor, Okta has the ability to upload a "secondary" certificate so we won't experience an outage. Unfortunately, I can't find any documentation so far about how to add a secondary SSO cert in Okta. Are they incorrect, or am I just not finding the solution?


  • b5n6c (b5n6c)

    Hi Timothy ,

    To generate a new saml certificate ,

    1. In the Okta Admin Console Session, click Applications
    2. Select the Application you want to work with
    3. SignOn > In the SAML signing Certificates Section Click on " Generate New Certificate"

     

    Expand Post
    • si6hv (si6hv)

      AD, will using that standard cert process automatically make it a secondary cert or will it over-write the existing cert (which doesn't expire until 2/3/23?

  • Paul S. (Okta, Inc.)

    Hello @si6hv (si6hv)​ Thank you for reacting out to our Community!

     

    Please also notice that if the SP changes their certificate, this should not impact your Okta application. Please also see this doc:

    https://support.okta.com/help/s/article/Does-Okta-need-to-make-any-changes-due-to-SAML-App-Vendor-s-SSO-certificate-replacement?language=en_US

     

    The Okta Community Catalysts Program is now live. Collect online badges when you participate in the Okta Help Center Questions community. Learn more here.

    Community members help others by clicking Upvote or Select as Best on responses. Try it today.

    Expand Post
This question is closed.
Loading
How to add a secondary cert for an Application's SSO / SAML