Downloading the Conga SAML Signing Certificate
Overview
Identity providers using the SAML 2.0 protocol use digital signatures to verify the authenticity of single sign-on (SSO) requests from providers such as the Application Portal. Following industry best-practices, the Conga signing certificate expires from time-to-time and must be replaced with a new certificate. When that occurs, your SAML-based identity provider will begin rejecting SSO requests from Conga until it is updated with the new certificate. If the identity provider is not updated, the rejected SSO requests will prevent your users from accessing their integrated Conga solutions.
There are two ways to obtain the relevant Conga signing certificates for SAML 2.0:
- Using the certificates embedded within the SAML XML metadata file generated by the Application Portal. For metadata retrieval instructions, select the appropriate option below:
- Downloading the certificate files directly, without any additional SAML metadata. This process is covered by the remainder of this document.
Downloading the SAML Signing Certificates
You may download a ZIP archive containing the currently available signing certificate(s) used by the Application Portal. Conga hosts different cloud Realms for customers depending upon their needs, each with a different certificate. Compare the base URLs used in your existing SAML configuration if you are unsure of the appropriate realm, then use the appropriate download URL from the following table:
| CONGA CLOUD REALM | APPLICATION PORTAL URL |
|---|---|
| AU REALM 1 | https://login.au1s1.congacloud.com/x/certificates.zip |
| EU1 | https://login.eu1s1.congacloud.com/x/certificates.zip |
| EU1 Preview | https://login.eu0s1.congacloud.com/x/certificates.zip |
| US REALM 1 | https://login.us1s1.congacloud.com/x/certificates.zip |
| US1 Preview | https://login.us0s1.congacloud.com/x/certificates.zip |
| E1 Subrealm | https://login.eu1s2.congacloud.com/x/certificates.zip |
| US1 Subrealm | https://login.us1s2.congacloud.com/x/certificates.zip |
Normally, the ZIP archive will contain the single certificate (*.CRT) file currently in use:
When the current certificate is nearing its expiry time, but not yet expired, the archive will contain both the current certificate and the new, pending certificate in separate folders.
Some identity providers allow configuring multiple signing certificates; in this case, installing the new certificate in advance may allow a seamless, zero-downtime transition. Other providers do not support this capability, so Conga will inform customers of the specific UTC time of the expected transition, in advance, so that the certificate change can be scheduled with your identity provider administrators to minimize downtime for your users.
