Request to Update Certificates / Certificate Expiration for Auth0 SAML Dashboard SSO Integrations
Last Updated:
Overview
The setup of a Dashboard Single Sign-On (SSO) Security Assertion Markup Language (SAML) connection to an enterprise Identity Provider includes configuring a signing certificate that eventually expires. Auth0 does not enforce the certificate expiration, so it can be used past its expiration date. However, administrators can request a certificate rotation via Auth0 Support.
Applies To
- Auth0
- Certificate Rotation
- Update Certificates
- Certificate Expiration
- SAML Dashboard SSO Integrations
Solution
How is a certificate rotation requested for SAML Dashboard SSO integrations?
Request a certificate rotation via a Support ticket. Provide the following information in advance to complete this task.
- The new signing certificate.
- A tentative date and time when the requestor is available to make the change.
Coordinate an exact date and time with the Support team to make the change simultaneously and avoid momentary access disruptions for the Dashboard administrators. Configuring more than one certificate at any given time is not supported.
NOTE: Auth0 allows the use of an expired certificate if it matches both the Identity Provider and Auth0. However, Identity Providers such as Microsoft Entra ID enforce specific behaviors upon expiration. When an existing certificate expires, and administrators generate a new certificate in Entra ID, Entra ID immediately uses the new certificate for signing tokens, even if it is not yet active. Auth0 rejects the SAML response because it receives an unknown certificate, resulting in an access outage.