Creating and updating the SP signing certificate for SAML authentication
To update the signing certificate in BMC Helix SSO Admin Console
- Log in to the BMC Helix SSO Admin Console.
- Navigate to General > Advanced tab.
- Enter the following details:
- Keystore File with the full path
- Keystore Password
- Signing Key Alias
- Click Save.
- Navigate to Realm, and select a realm configured for SAML authentication.
- On the Authentication tab, click View Metadata and verify whether the SP metadata is updated with the new signing certificate.
To update the SP metadata at the IdP side
- Export the SP metadata and save it to a local file.
- Share the exported SP metadata and the new signing certificate with the IdP team.
- If you have Active Directory Federation Services (AD FS) configured as the IdP, perform the following steps to add the new signing certificate:
- Open the context menu for the relying party trust and select the Update from Federation Metadata check box.
- Open the Properties dialog of the relying party for BMC Helix SSO .
- Navigate to the Signature tab, and click Add.
- Select the new signing certificate file, and click OK.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*