{"id":93273,"date":"2023-07-06T19:49:56","date_gmt":"2023-07-06T23:49:56","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=93273"},"modified":"2023-08-22T11:52:29","modified_gmt":"2023-08-22T15:52:29","slug":"rotate-sso-certs","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/rotate-sso-certs","title":{"rendered":"Rotate SSO Application Certificates, SCIM Token Keys, & OIDC Tokens"},"content":{"rendered":"\n
<\/p><\/div>
The following are recommended actions for all JumpCloud organizations using SSO applications:<\/p>\n\n\n\n
All SAML SSO integrations require a certificate and private key pair. This certificate and private key pair can be auto-generated by JumpCloud, or you can upload your own. In addition, some Service Providers require a Service Provider Certificate. <\/p>\n\n\n\n
<\/p><\/div>
Admins should review your Service Provider requirements prior to taking these steps to limit downtime and prevent lockouts.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
<\/p><\/div>
To rotate the cert for M365, please refer to the specific steps in the SSO with M365<\/a> article.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Complete the following steps for each SAML SSO app integration you have configured for which you would like to use a JumpCloud-created certificate and private key pair. <\/p>\n\n\n\n <\/p><\/div> When you upload a new certificate, your private key is wiped. You need to upload a new private key after you upload a certificate.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Depending on how the Service Provider accepts certificates, do one of the following to upload the new certificate in Service Provider\u2019s application.<\/p>\n\n\n\n To update the IdP certificate in the Service Provider using a metadata URL<\/strong><\/p>\n\n\n\n If the Service Provider supports updating the configuration and certificate from a metadata file URL: <\/p>\n\n\n\n To update the IdP certificate in the Service Provider<\/strong> using a metadata file<\/strong><\/p>\n\n\n\n If the Service Provider supports extracting the certificate from the metadata file: <\/p>\n\n\n\n To update the IdP certificate in the Service Provider<\/strong> by uploading the certificate<\/strong><\/p>\n\n\n\n If the Service Provider supports uploading the IdP certificate file (.pem):<\/p>\n\n\n\n To update the IdP certificate in the Service Provider<\/strong> by copying and pasting the contents of the certificate file<\/strong><\/p>\n\n\n\n If the Service Provider supports copying and pasting the contents of the certificate file (.pem):<\/p>\n\n\n\n <\/p><\/div> Refer to the Service Provider<\/strong> documentation to determine if \u201c—–BEGIN CERTIFICATE—–\u201d and —–END CERTIFICATE—– should or should not be included when pasting the certificate contents.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Some Service Providers require a Service Provider certificate. After you have updated the new JumpCloud IdP certificate, complete the following steps for each SAML SSO app integration you have configured that requires a Service Provider certificate. <\/p>\n\n\n\n To update the Service Provider<\/strong> certificate in JumpCloud by uploading the Service Provider<\/strong> metadata file<\/strong><\/p>\n\n\n\n To update the Service Provider<\/strong> certificate in JumpCloud by uploading the certificate file<\/strong><\/p>\n\n\n\n <\/p><\/div> For a pre-built SSO integration, if there is no section or button, a Service Provider certificate is not required.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Prerequisites<\/strong><\/p>\n\n\n\n Steps to take in JumpCloud:<\/p>\n\n\n\n Steps to take in Service Provider:<\/p>\n\n\n\n Steps to take in JumpCloud:<\/p>\n\n\n\n Learn More:<\/p>\n\n\n\n Prerequisites<\/strong><\/p>\n\n\n\n Steps to take in JumpCloud:<\/p>\n\n\n\nTo regenerate a JumpCloud-created certificate and private key pair<\/strong><\/h4>\n\n\n\n
\n
To update the IdP certificate in the Service Provider<\/strong><\/h4>\n\n\n\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
To update the Service Provider<\/strong> certificate in JumpCloud<\/strong><\/h4>\n\n\n\n
\n
\n
\n
Rotate SCIM Token Keys<\/h2>\n\n\n\n
\n
\n
<\/li>\n\n\n\n\n
\n
\n
Regenerate OIDC Secrets<\/h2>\n\n\n\n
\n