---
title: Maintain the SAML Certificate
description: SAML Certificate
---

[Skip to content](https://support.econz.net/customer/maintain-the-saml-certificate#main-content)

English

Show submenu for translations

[Customer portal](https://support.econz.net/portal?hsLang=en)

![logo.jpg\]](https://support.econz.net/hs-fs/hubfs/logo.jpg?height=40&name=logo.jpg)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Customer portal](https://support.econz.net/portal)
- Go to Econz Website

 Go to Econz Website

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://support.econz.net/customer?hsLang=en)
2. [Google Workspace](https://support.econz.net/customer/google-workspace?hsLang=en)
3. [Security](https://support.econz.net/customer/google-workspace?hsLang=en#security)

# Maintain the SAML Certificate

## SAML Certificate

Your SAML applications use X.509 certificates to confirm the authenticity and integrity of messages shared between the Identity Provider (IdP) and the Service Provider (SP).

As a Super administrator, you can use the Admin console to:

- Easily view the X.509 certificates in use by your SAML applications
- Identify the X.509 certificates that are about to expire

Create new certificates and assign them to your SAML applications. This is called *certificate rotation*.

#### **Why rotate SAML certificates?**

X.509 certificates have a five-year lifetime. You should rotate a certificate if it's about to expire, or if it becomes compromised. If a certificate expires before you rotate it, your users won't be able to use SSO to sign in to any SAML applications that use that certificate until you replace it with a new certificate. 

Before the expiration of your default certificate, add a second certificate with a new 5-year lifespan, then switch your apps from the expiring certificate. Having two valid certificates allows you to switch some apps over to the new certificate as a test, without affecting apps that are still using the older certificate. When you've moved all apps over to the new certificate, you can delete the old certificate.

**Important:** After assigning a new certificate to a SAML app in the Admin console,  you also need to update the corresponding SP side SSO configuration with the new certificate, or SSO with the app will fail.

#### **How to Manage SAML Certificates?**

Your account has one default certificate you can use for all your SAML apps. You can add a second certificate, or delete one or both certificates and generate new certificates:

- Sign in to the Google Admin console with the Super administrator account.
- In the Admin console, go to Menu\> **Security**\> **Authentication**\> **SSO with SAML applications.**

The **Certificates** section shows the current X.509 certificates. The certificate name, expiration date, contents, and SHA-256 fingerprint are shown. Use the buttons at the right to copy, download, or delete a certificate.

- (Optional) If you have only one certificate, click **Add another certificate** to create a second certificate.  
  **Note**: The most recently generated (newest) certificate becomes the default certificate used to set up SSO for new SAML apps.

- To **Delete a certificate**
- Click **Delete certificate**. Deleting a certificate has these results:
- If you have one certificate, a new certificate is automatically generated to replace it.
- if you have two certificates and delete certificate 1, certificate 2 replaces certificate 1.

If the certificate you're deleting is used by any installed SAML apps, a window lists the affected apps, and warns you that SSO with the app will be unavailable until you assign a new certificate to those apps.

**Tip:** SAML certificate events (deletion, creation, changing a SAML app's assigned certificate) are logged in the [Admin audit log](https://support.google.com/a/answer/4579579).

 

![](https://lh6.googleusercontent.com/Il53HMVzurxUnBvZlbLC4Xp-gUXYFH7iZjlJefCWk21_vHUzorQuo4s9Kf0bG0c1pLgNBUU59w6c90mqKtTAx0tEXhoGaRyD9_ekFC4-xvbyQV91gMEdV-g_FNNQyl84EMk09K66dbtfWVpcm8-5Azc)

#### **Update the certificate used by a SAML application**

If you replace a certificate used by any of your SAML apps, follow the steps below to assign the new certificate to the affected apps. You'll also need to update the certificate in the SSO settings for those apps on the SP’s administrative website.

- In the Admin console, go to **Menu** \> **Apps** \> **Web and mobile apps**.
- Click the SAML app to open its Settings page.
- Click **Service Provider details**.  
  Under **Certificate**, the current certificate used by the app is shown, including the certificate ID and expiration date. If you deleted the certificate that was initially used to set up the app, you'll see the warning **No certificate assigned**.
- Click the **Down arrow** and choose a certificate.
- (Optional) If there's no other certificate available, or you need to create new certificates, click **Manage Certificates** and follow the instructions in **Manage SAML Certificate** above.
- After changing the certificate assigned to the SAML app, make sure to also update the app's SSO configuration with the new certificate on the Service Provider's website. SSO with the SAML app won't work until the SP-side configuration is also updated.

**Important**: After you replace a certificate, it may take up to 24 hours for the new certificate to be available for use by your SAML applications.

 

![](https://lh4.googleusercontent.com/J8OwULPn4mbKvtatR_7-3ti21hkc0EZgjU5QC36UeaeZvh2dY-JzsiY9GYuptU4ZfpoiYS9smG_OVuyHpjx3lsUI6bXJQ2qgYPJwClnRE2CpzER4mpMUWZTH9gVhcHxGCjP6sBA78PfOnI95WmKN6N0)

 

Please check the supporting article for reference.

[Maintain SAML Certificates](https://support.google.com/a/answer/7394709)

- [Google Workspace](https://support.econz.net/customer/google-workspace?hsLang=en#main-content)

    - [Reset and recover passwords](https://support.econz.net/customer/google-workspace?hsLang=en#reset-and-recover-passwords)
    - [Email issue](https://support.econz.net/customer/google-workspace?hsLang=en#email-issue)
    - [catch-all address](https://support.econz.net/customer/google-workspace?hsLang=en#catch-all-address)
    - [Download Google Data](https://support.econz.net/customer/google-workspace?hsLang=en#download-google-data)
    - [Gmail](https://support.econz.net/customer/google-workspace?hsLang=en#gmail)
    - [MX Records](https://support.econz.net/customer/google-workspace?hsLang=en#mx-records)
    - [Company Logo](https://support.econz.net/customer/google-workspace?hsLang=en#company-logo)
    - [Sharing drive files to the trusted domains](https://support.econz.net/customer/google-workspace?hsLang=en#sharing-drive-files-to-the-trusted-domains)
    - [Mobile Device Management](https://support.econz.net/customer/google-workspace?hsLang=en#mobile-device-management)
    - [Restrict emails based on a size](https://support.econz.net/customer/google-workspace?hsLang=en#restrict-emails-based-on-a-size)
    - [Create Google Calendar Event](https://support.econz.net/customer/google-workspace?hsLang=en#create-google-calendar-event)
    - [less secure app](https://support.econz.net/customer/google-workspace?hsLang=en#less-secure-app)
    - [Drive & Docs](https://support.econz.net/customer/google-workspace?hsLang=en#drive-docs)
    - [Users](https://support.econz.net/customer/google-workspace?hsLang=en#users)
    - [Install GCPW](https://support.econz.net/customer/google-workspace?hsLang=en#install-gcpw)
    - [Add email aliases for user from google admin console](https://support.econz.net/customer/google-workspace?hsLang=en#add-email-aliases-for-user-from-google-admin-console)
    - [Set up Google Workspace user signatures in Gmail](https://support.econz.net/customer/google-workspace?hsLang=en#set-up-google-workspace-user-signatures-in-gmail)
    - [Add or remove printers](https://support.econz.net/customer/google-workspace?hsLang=en#add-or-remove-printers)
    - [New updates to Google Workspace](https://support.econz.net/customer/google-workspace?hsLang=en#new-updates-to-google-workspace)
    - [DNS](https://support.econz.net/customer/google-workspace?hsLang=en#dns)
    - [DNS Records](https://support.econz.net/customer/google-workspace?hsLang=en#dns-records)
    - [Admin roles](https://support.econz.net/customer/google-workspace?hsLang=en#admin-roles)
    - [Security](https://support.econz.net/customer/google-workspace?hsLang=en#security)
    - [Forms & Surveys](https://support.econz.net/customer/google-workspace?hsLang=en#forms-surveys)
    - [password](https://support.econz.net/customer/google-workspace?hsLang=en#password)
    - [Calendar](https://support.econz.net/customer/google-workspace?hsLang=en#calendar)
    - [Google vault](https://support.econz.net/customer/google-workspace?hsLang=en#google-vault)
    - [har file](https://support.econz.net/customer/google-workspace?hsLang=en#har-file)
    - [Cloud Data Sync](https://support.econz.net/customer/google-workspace?hsLang=en#cloud-data-sync)
    - [LDAP](https://support.econz.net/customer/google-workspace?hsLang=en#ldap)
    - [Routing](https://support.econz.net/customer/google-workspace?hsLang=en#routing)
    - [Data Migration](https://support.econz.net/customer/google-workspace?hsLang=en#data-migration)
    - [Organizational Unit(OU)](https://support.econz.net/customer/google-workspace?hsLang=en#organizational-unitou)
    - [License and subscription](https://support.econz.net/customer/google-workspace?hsLang=en#license-and-subscription)
    - [GWSMO](https://support.econz.net/customer/google-workspace?hsLang=en#gwsmo)
    - [Report and Audit](https://support.econz.net/customer/google-workspace?hsLang=en#report-and-audit)
    - [SMTP](https://support.econz.net/customer/google-workspace?hsLang=en#smtp)
    - [GWMME](https://support.econz.net/customer/google-workspace?hsLang=en#gwmme)
    - [password sync](https://support.econz.net/customer/google-workspace?hsLang=en#password-sync)
    - [Google Sites](https://support.econz.net/customer/google-workspace?hsLang=en#google-sites)
    - [Google services](https://support.econz.net/customer/google-workspace?hsLang=en#google-services)
    - [jamboard](https://support.econz.net/customer/google-workspace?hsLang=en#jamboard)
    - [Google Add-ons](https://support.econz.net/customer/google-workspace?hsLang=en#google-add-ons)
    - [GCPW](https://support.econz.net/customer/google-workspace?hsLang=en#gcpw)
    - [Keep](https://support.econz.net/customer/google-workspace?hsLang=en#keep)
    - [outlook](https://support.econz.net/customer/google-workspace?hsLang=en#outlook)
    - [Devices](https://support.econz.net/customer/google-workspace?hsLang=en#devices)
    - [Apps](https://support.econz.net/customer/google-workspace?hsLang=en#apps)
    - [Spam, phishing, and malware](https://support.econz.net/customer/google-workspace?hsLang=en#spam-phishing-and-malware)
    - [Windows](https://support.econz.net/customer/google-workspace?hsLang=en#windows)
    - [Meet Hardware](https://support.econz.net/customer/google-workspace?hsLang=en#meet-hardware)
    - [user settings](https://support.econz.net/customer/google-workspace?hsLang=en#user-settings)
    - [Google takeout](https://support.econz.net/customer/google-workspace?hsLang=en#google-takeout)
    - [Chrome Device Management](https://support.econz.net/customer/google-workspace?hsLang=en#chrome-device-management)
    - [networks](https://support.econz.net/customer/google-workspace?hsLang=en#networks)
    - [Chrome Enterprise Management](https://support.econz.net/customer/google-workspace?hsLang=en#chrome-enterprise-management)

[![](https://support.econz.net/hs-fs/hubfs/econz%20logo.png?width=600&height=164&name=econz%20logo.png)](http://econz.cloud)

Help Center

Copyright © 2026, Econz IT Services Pvt Ltd