Update your SAML single sign-on (SSO) certificate on the Invoca side so it stays in sync after your identity provider (IdP) rotates its certificate.
Why this is needed
If your organization rotates its identity provider (IdP) certificate as part of your SAML single sign-on (SSO) setup, that same update needs to be applied on the Invoca side too, so your SSO login continues to work without interruption. Which steps you follow depends on whether your network uses Legacy SAML SSO or Next-Gen SSO.If you’re on Next-Gen SSO
Certificate updates are self-service:- Log in to Invoca and go to Settings > Users. Click the kebab menu (three vertical dots) and select SSO Settings.
- Click Edit SSO Configuration.
- Re-enter your IdP’s metadata URL, or manually upload the new X.509 certificate.
- Save your changes.
If you’re on Legacy SAML SSO
Certificate updates are also self-service:- Get your IdP’s new X.509 certificate and run it through a fingerprint calculator to get its SHA-1 fingerprint — see How to Find Your SHA-1 or SHA-256 Fingerprint for Your SSO Settings for that step.
- Log in to Invoca and go to Settings > Users. Click the menu button and select SSO Settings.
- Enter the new fingerprint, with tuples separated by colons, in the SHA-1 Fingerprint field.
- Save your changes.