Rotate SAML Certificate
SIGNING CERTIFICATE REPLACEMENT/ROTATION (SAML-BASED PROVIDERS ONLY)
During initial configuration, at least one signing certificate must be configured. Your company's policies may require the signing keys to be rotated or changed on occasion. The Application Portal supports zero downtime rotation of your SAML identity provider's signing certificates when you follow these steps to upload the new certificate before applying it to the identity provider. When more than one certificate is configured, Conga will accept SAML assertions that are verified with digital signatures matching either certificate.
- Scroll down to the Security/Certificates section.
- Paste your new or updated certificate; it must be in PEM text format, including the lines indicating BEGIN and END of the certificate.
- Do not remove the old certificate until testing has confirmed that the new certificate is working correctly.
- Follow the steps indicated in Saving and Testing Changes of IdP Management.
- Once everything is working as expected using the new certificate, use a similar procedure to remove the old certificate.
