cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1476
Views
0
Helpful
4
Replies

Cisco Umbrella Expire Certificate warning

sv7
Level 3
Level 3

HI All,

Received below mail from cisco for umbrella deployed in my Organisation. Can anyone let me know what it is Exactly.

 

Hello there,

We are writing to let you know the Umbrella SAML certificate used for Umbrella SWG user identification will expire on the 26th of September 2022 00:00 (UTC). Your organization has been identified as using the Umbrella SAML certificate. This renewed certificate is now available. You have until the 26th of September to update your identity provider (IdP) with the renewed Umbrella SAML certificate.  

 

Updating the certificate is essential to avoid SAML user authentication failures and loss of internet access for those users. 

 

To download the updated SAML metadata please go here, and to download the updated Certificate please go here, You can find more information from the Umbrella Support Knowledge Base here.

 

Since this will be an annual task, from this year onwards the Umbrella metadata URL will remain constant. When the certificate is renewed in future years, we will update the metadata without changing the URL. This approach will support those IDPs, like ADFS and PingID, that can monitor the relying party metadata URL and automatically update when the relying party metadata is updated with a new certificate.  

  

Note:  Some Identity Providers do not perform validation of SAML request signatures and therefore do not require our new certificate.  If in doubt, please contact your Identity Provider vendor for confirmation. 

4 Replies 4

sv7
Level 3
Level 3

Any help please

That is to let you know that you need to upload the new Umbrella certificate available for download and to set the new SAML metadata. You would have done that previously when you first configured the SAML authentication/integration with Umbrella. Essentially, you need to go to the same places and update those details. I don't have access to any Umbrella console right now to share the exact steps to find those details, but I think they are under Settings > Authentication > SAML in your Umbrella management console.

Hi Aref,

In my organisation im not using any SAML integration. My users are authenticated using AD only. Does still it applies to my network ?

Hi there, I can't tell as I have no visibility of your network design :), however, if you don't use SAML then I think you are safe to ignore that warning.