Updating Your SSO Certificate or Identity Provider Details
When your organisation renews its Single Sign-On (SSO) certificate, you normally do not need to send the new certificate or an updated Metadata XML file to ePlatform.
Action is only required when important identity-provider connection details change, such as the authentication endpoint or Entity ID.
When no update is required
You do not normally need to submit a new certificate or contact ePlatform Support when:
- you are renewing an expiring SSL or SAML certificate in your existing identity provider;
- the SSO Authentication URI or Endpoint URL remains exactly the same;
- the Entity ID or Issuer URL has not changed; and
- you are continuing to use the same identity provider.
This includes standard certificate renewals in providers such as Microsoft Entra ID, Okta, and Google Workspace.
When the established SSO Authentication URI and other connection details remain unchanged, patrons can continue signing in without an update to the ePlatform configuration.
When to contact ePlatform Support
Contact ePlatform Support if the certificate renewal or identity-provider change also alters the structure of your SSO connection.
Contact Support when there is:
- a change to the SSO Authentication URI or Endpoint URL;
- a change to the Entity ID or Issuer URL;
- a change to the SSO metadata used for the connection; or
- a move to a different identity provider.
| Change | Action required |
|---|---|
| Certificate renewed but the Authentication URI and Entity ID remain unchanged | No action is normally required. |
| Authentication URI or Endpoint URL changes | Contact ePlatform Support before the change. |
| Entity ID or Issuer URL changes | Contact ePlatform Support before the change. |
| Your organisation moves to a different identity provider | Contact ePlatform Support before the migration. |
Changing identity providers
Contact ePlatform Support if your organisation is moving from one identity provider to another, such as moving from ADFS to Okta.
Submit the new connection information before the planned migration date so the ePlatform configuration can be updated and tested.
Do not treat a change of identity provider as a standard certificate renewal. A new provider may use a different authentication endpoint, Entity ID, metadata file, or attribute configuration.
Information to provide
If your SSO connection details are changing, submit a support request and include:
- your ePlatform library name;
- the name of your current identity provider;
- the name of the new identity provider, if applicable;
- the new SSO Authentication URI or Endpoint URL;
- the new Entity ID or Issuer URL;
- the updated Metadata XML file;
- the planned change or migration date; and
- the contact details of the person coordinating the technical change.
Certificate renewal FAQs
Do we need to send ePlatform every renewed SSO certificate?
In most cases, no. If you are renewing the certificate in your existing identity provider and the Authentication URI and Entity ID remain unchanged, no ePlatform update is normally required.
Will patrons experience downtime when our SSO certificate renews?
A standard certificate renewal should not interrupt patron access when the existing SSO Authentication URI and other connection details remain unchanged.
What should we do if the Authentication URI changes?
Submit a support request before the change. Include the new Authentication URI and updated Metadata XML file so the ePlatform configuration can be updated.
What if we are unsure whether our SSO details are changing?
Contact ePlatform Support and provide the proposed identity-provider changes. The team can confirm whether the ePlatform configuration needs to be updated.
Need help?
If you are unsure whether a certificate renewal or identity-provider change affects your SSO connection, submit a support request or email support@eplatform.co.