cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4903
Views
0
Helpful
0
Comments
kwelkerm
Cisco Employee
Cisco Employee

The Umbrella SAML certificate used for SWG User Identification will expire on May 13, 2025, 07:00:46UTC. This certificate will be renewed and made available on April 11, 2025. This will allow time from then until the 13th of May for you to update your identity provider (IdP) with the renewed Umbrella SAML certificate. 

Updating the certificate is essential to avoid SAML user authentication failures and loss of internet access for those users.

This first communication is intended to inform you of this upcoming event and provide time to plan and schedule the certificate update task with your Identity Provider. 

A further confirmation update will be published once the certificate is renewed and made available. 

This is an annual task; however, the Umbrella metadata URL will remain constant from previous years. Therefore, we recommend utilizing the metadata URL to automatically acquire the renewed certificate instead of using a manual import process. When the certificate is renewed, we will update the metadata without changing the metadata URL. This method will support identity providers, like ADFS and Ping Identity, that can monitor the relying party metadata URL and automatically update when the relying party metadata is refreshed with a new certificate.

For more information on renewal options, see https://docs.umbrella.com/umbrella-user-guide/docs/saml-certificate-renewal-options

Note:  Some Identity Providers do not perform validation of SAML request signatures and therefore do not require our new certificate. If in doubt, please contact your Identity Provider vendor for confirmation.

If you have any questions, please contact your support contact.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: