Cisco Secure Access Help Manage Certificates Manage SAML VPN Service Provider Certificate Rotation

Last updated: Aug 29, 2025

Manage SAML VPN Service Provider Certificate Rotation

Secure Access manages the expiration of service provider certificates for various connection methods and SAML IdP integrations. Service provider certificates are used to establish the trust relationship between the service provider and the IdP. The IdP authenticates users that connect to Secure Access with Virtual Private Networks (VPNs) with a configured VPN profile.

When Secure Access retires a service provider certificate, you need to rotate the service provider certificate used by your identity provider (IdP) to ensure admins and end users maintain successful access to applications.

Note: You must download the new Service Provider certificate, update your IdP with this new certificate, and activate the certificate within 24 hours before the current certificate expires. Failure to do this will result in SAML user authentication and connection failures.