Skip to main content
Dilipan M (Equiniti) a posé une question dans #SSO

My single sign on shows two different expiration date.

When I checked the SAML Single Sign On settings page in setup, for the field 'Identity Provider Certificate', It shows the following value 'CN=Microsoft Azure Federated SSO Certificate

Expiration: 4 Jul 2026 13:10:37 GMT'

 

I then opened the certificate itself, present on the field Request Signing Certificate, it says that the expiration date is in 2024.

 

Which is the true expiration date?

 

I checked with my Identity Provider team, they said it is 2026, but want to double check why it is showing 2024 in SF.

 

#SSO  #SSO Setup  #Single Sing-on  #Security  #Identity & Access Management

1 réponse
  1. 21 févr. 2024, 11:23
    Those are two different types of certificate. Request signing certificate could be used by your IDP to verify the Auth N request coming from Service provider (which is Salesforce in this case). A lot of cases IDP may not verify this certificate. You can check with your IDP team if they use SF request signing certificate for auth N request(For SP initiated SSO). The second certificate is the IDP certificate which is provided by your IDP, when IDP posts SAML response, they sign response with that certificate, and then Salesforce can use certificate uploaded in SF to verify the response to make sure it’s coming from right source.
0/9000