Skip to main content

SAML certificate expiry

Guidance on updating the SAML certificate date on a site.

Liam Smith avatar
Written by Liam Smith
Updated over 2 weeks ago

⚠️ Important: The below guidance is only applicable to super administrators on LMS² sites.

Why the SAML certificate needs to be updated

Certificates used for SAML are configured with regular expiry periods to maintain security standards. As the expiry date approaches, a renewal process is required to switch to a new certificate with a refreshed validity period.

Since SAML relies on public/private certificate pairs for token signing and verification, the public certificate must also be updated within client-managed systems that integrate with Access LMS Evo via SAML. This ensures uninterrupted authentication and secure communication between systems.


Switching to the renewed certificate

Switching to the renewed certificate in Access LMS Evo requires the super administrator system role. The steps outlined below enable early access to the renewed public certificate, allowing time to update the integrating system before completing the switch in Access LMS Evo. This approach reduces the risk of extended downtime caused by mismatched configurations.

📌 Note: During the brief window between updating the public certificate in the integrating system and switching to the renewed certificate in Access LMS Evo, the SAML integration will temporarily stop functioning. This disruption should last only a few minutes, as the switch within Access LMS Evo can be performed instantly

To perform the switch, please follow the below steps.

  1. Switch to admin view.

  2. Click Settings, then click Global Settings.

  3. Click the Manage Features tab, then search for SAML, then click SAML Configuration tile.

  4. Click Edit on For your Identity or Service provider.

  5. If configured provider isn't using the latest Access Group signing certificate, click Update To Latest Certificate.

  6. Click Download Certificate to get the renewed Access LMS Evo public certificate.

  7. Update the Access LMS Evo public certificate in your system that integrates with Access LMS Evo via SAML.

    • 📌 Note: After changing the certificate in the system, SAML integration stops working until you complete the next step of this process.

  8. Switch over Access LMS Evo configuration to use the renewed certificate that matches the public certificate downloaded by clicking Update Certificate.

Did this answer your question?