Update SSO certificate

Last updated on Dec 16, 2024

If you have set up SSO for your identity provider (IdP) with the Adobe Admin Console and your end users can't log in to their Adobe apps and services, the SAML-certificate may have expired.

Issue

You face any of the following issues:

  • End users are logged out and can't sign in to the Adobe Creative Cloud web, mobile, or desktop apps.
  • When they attempt to sign in, end users see error messages such as: “SAML certification validation failed” or “The digital signature in the SAML response did not validate with the identity provider's certificate.”
  • Admins can't add, remove, or manage users or product profiles.
  • Admins want to renew a SAML certificate that's about to expire.

Cause

In a SAML exchange, the two entities that are involved are:

  • Identity Provider (IdP): the IdP certificate is owned and managed by the customer inside their own IdP (AD FS, Okta, Shibboleth) and is uploaded into the Admin Console.
  • Adobe, acting as a Service Provider (SP): Adobe entities are managed in the Admin Console and uploaded to the customer's IdP.

Both entities have their respective certificates, which are used to establish trust.
If you have set up SSO for your identity provider (IdP) with the Adobe Admin Console and your end users cannot log into their Adobe apps and services, the SAML certificate may have expired.

Admin Console notification

Adobe informs you when an Adobe-generated certificate is set to expire or has expired, with a banner notification in the Admin Console and a status update per directory. To view the status of a SAML certificate, navigate to Settings > Identity Settings and review the Status column of the Directories tab.

Resolution

Generate or update a certificate

If your certificates have expired or are about to expire, you can directly update the federation setup via the Admin Console. The SAML certificates are updated along with the SAML setup.

Note

If your IdP does not check the validity of the certificate, no action is required.

As a System Admin, you can directly update and manage self-signed certificates from the Admin Console by following these steps:

On the Admin Console, navigate to Settings >Identity > (Directory Name)> Authentication.

Select Edit and then select Next.

View available certificates and their status. You can choose to generate a new certificate or a new certificate signing request.

Note

A self-signed certificate is more convenient and follows security best practices. Choose a self-signed certificate unless your organization has specific requirements that a self-signed certificate can't satisfy.

Select Generate New CertificateA new SAML certificate will be generated within the selected federated directory for an active SAML configuration.

To create a new signing request instead, select Create a certificate signing request. In the dialog that displays, enter the details from your certificate authority (CA).

You must complete the process with your CA for it to take effect with the SAML certificate. Go to Actions and select Complete. Upload the certificate file from the certificate authority, select Complete, and then select Done.

Once a certificate is successfully created, additional actions become available, including Set as default, Activate, Deactivate, Download metadata, Download certificate, and Delete.

If your IdP supports multiple certificates, follow these steps without any sign-in interruptions:

Rotate a certificate with multi-certificate IdP support

Upload the new certificate in addition to the old one into your IdP.

Set the new certificate as default in the Adobe Admin Console.

Test sign-in.

Remove the old certificate from your IdP configuration.

Disable the old certificate.

Note

We recommend disabling rather than deleting, since deleting a certificate is irreversible.

Rotate a certificate without multi-certificate IdP support

If your IdP does not support multiple certificates, choose a downtime interval to perform the renewal:

Upload the new certificate into your IdP.

Set the new certificate as default in the Adobe Admin Console.

Test sign-in.

Disable the old certificate.

If you don't encounter any issue, delete the old certificate.

Note

We recommend waiting some time before deleting the old certificate, since deleting certificates is irreversible.

Audit logs

Actions related to the creation and management of certificates can be found in the audit logs. To view the audit logs, go to the Admin Console and navigate to Insights > Logs > Audit log.