Updating a Yandex Cloud SAML certificate in an identity federation
Note
This guide describes how to update a SAML certificate issued by Yandex Cloud and used to sign requests from an identity federation to an IdP provider. To update an IdP provider certificate used to sign requests from the IdP provider to an identity federation, see Adding an IdP server certificate to a federation.
A Yandex Cloud SAML certificate is valid for 5 years. Yandex Cloud generates a new SAML certificate automatically before the previous certificate's expiration date.
Make sure to start using the new SAML certificate before the previous one expires.
To start using the new SAML certificate in a Yandex Cloud Organization identity federation:
-
Log in to Yandex Cloud Organization
with an administrator or organization owner account. -
In the left-hand panel, select
Federations. -
In the list that opens, select the identity federation of interest.
If the Yandex Cloud SAML certificate was reissued and requires a replacement, the
icon will appear in the Sign authentication requests field to the left of Download certificate. If the icon is orange, it means the previous certificate is still valid; if red, the previous certificate has expired. In both these cases, you need to update the Yandex Cloud SAML certificate in the identity federation and on the IdP server. -
In the top-right corner, click
Update.In the window that opens, you will see two certificates in the SAML certificate section under Advanced: the current one and the new (reissued) one. Expiration dates will be specified for both. The current one will also feature a warning that you need to download and install a new certificate.
-
To the right of the new (reissued) SAML certificate’s expiration date, click
Download.Tip
Track SAML certificate expiration dates and always install new a new certificate before the current one expires.
Before you proceed to the next step, deliver the downloaded Yandex Cloud SAML certificate to the IdP server. To learn how to do this, consult the identity provider's documentation or contact their support.
-
Once you have delivered the new SAML certificate to your IdP server, select the new (reissued) SAML certificate in the federation settings update form and click Save.