Conga Product Documentation

Welcome to the new doc site. Some of your old bookmarks will no longer work. Please use the search bar to find your desired topic.

Downloading the Conga SAML Signing Certificate

Overview

Identity providers using the SAML 2.0 protocol use digital signatures to verify the authenticity of single sign-on (SSO) requests from providers such as the Application Portal. Following industry best-practices, the Conga signing certificate expires from time-to-time and must be replaced with a new certificate. When that occurs, your SAML-based identity provider will begin rejecting SSO requests from Conga until it is updated with the new certificate. If the identity provider is not updated, the rejected SSO requests will prevent your users from accessing their integrated Conga solutions.

There are two ways to obtain the relevant Conga signing certificates for SAML 2.0:

Downloading the SAML Signing Certificates

You may download a ZIP archive containing the currently available signing certificate(s) used by the Application Portal. Conga hosts different cloud Realms for customers depending upon their needs, each with a different certificate. Compare the base URLs used in your existing SAML configuration if you are unsure of the appropriate realm, then use the appropriate download URL from the following table:

CONGA CLOUD REALMAPPLICATION PORTAL URL
AU REALM 1https://login.au1s1.congacloud.com/x/certificates.zip
EU1https://login.eu1s1.congacloud.com/x/certificates.zip
EU1 Previewhttps://login.eu0s1.congacloud.com/x/certificates.zip
US REALM 1https://login.us1s1.congacloud.com/x/certificates.zip
US1 Previewhttps://login.us0s1.congacloud.com/x/certificates.zip
E1 Subrealmhttps://login.eu1s2.congacloud.com/x/certificates.zip
US1 Subrealmhttps://login.us1s2.congacloud.com/x/certificates.zip

Normally, the ZIP archive will contain the single certificate (*.CRT) file currently in use:



When the current certificate is nearing its expiry time, but not yet expired, the archive will contain both the current certificate and the new, pending certificate in separate folders.

Some identity providers allow configuring multiple signing certificates; in this case, installing the new certificate in advance may allow a seamless, zero-downtime transition. Other providers do not support this capability, so Conga will inform customers of the specific UTC time of the expected transition, in advance, so that the certificate change can be scheduled with your identity provider administrators to minimize downtime for your users.