You can paste a PEM certificate into a X.509 Certificate form so the identify provider can verify communications with the service provider.

Before you begin

Role required: admin

About this task

The IdP's certificate is located within the IdP's metadata. The IdP developer determines where the certificate metadata resides when creating the local IdP.

Note: Certificates for single-sign on should always be in PEM format to work with SAML certificates.

Procedure

  1. Navigate to All > SAML Single Sign-on > Certificate.
  2. Fill in the form fields (see table).
  3. Click Save.
    Pasting in the PEM certificate
    Note: The integration does not currently sign the certificate in communications between the instance and the IdP.

What to do next

Click Validate Stores/Certificates to test the trust store and certificate.