Published Date: July 23, 2026
Audience: Everyone
Products and Versions Covered:
- Jama Connect® - All Versions
- Cloud/CVC
- Self-hosted
Summary
If your organization uses Security Assertion Markup Language (SAML) Single Sign-On (SSO) with Jama Connect®, your identity provider's signing certificate will eventually expire and require renewal. Most identity providers notify administrators when a signing certificate is approaching expiration or provide tools to generate a replacement certificate. If Jama Connect is not updated with the new certificate information before the existing certificate expires, users may be unable to authenticate using SSO.
For Cloud-hosted Jama Connect environments, Jama Support manages the SAML configuration on your behalf. Your organization is responsible for renewing the signing certificate in your Identity Provider (IdP), while Jama Support updates your Jama Connect configuration using the new metadata.
For Self-hosted environments, your Jama administrator is responsible for updating both the Identity Provider and the Jama Connect SAML configuration.
This article explains how the certificate renewal process works, the responsibilities of each party, and the steps required to complete the update with minimal disruption.
Understanding the Certificate Renewal Process
When SAML authentication is enabled, two systems participate in the trust relationship:
- Your Identity Provider (IdP) (such as Microsoft Entra ID, Okta, PingFederate, or Google Cloud Identity) authenticates users and signs SAML assertions using its signing certificate.
- Jama Connect validates those signed assertions using the certificate information contained in your Identity Provider metadata.
Because the signing certificate belongs to your Identity Provider, certificate renewal always begins within your IdP. Once the certificate has been renewed, Jama Connect must receive the updated metadata so it can continue trusting authentication requests.
Important: Certificate renewal is a normal part of operating any SAML-based Single Sign-On solution. Certificate lifetimes vary by Identity Provider and organizational policy, so many administrators encounter this process only every several years.
Responsibilities During Certificate Renewal
The certificate renewal process is a shared responsibility between your organization and Jama Support.
Cloud-hosted Jama Connect
| Responsibility | Customer | Customer Support |
| Renew or generate a new SAML signing certificate in the Identity Provider | √ | |
| Export or provide updated IdP metadata (Metadata URL or XML) | √ | |
| Submit a Jama Support request | √ | |
| Update the SAML configuration in Jama Connect | √ | |
| Coordinate a maintenance window, if needed | √ | |
| Validate authentication after the update | √ | √ |
| Troubleshoot authentication issues | √ |
Note: Cloud customers cannot update the SAML configuration within Jama Connect themselves. Jama Support performs these administrative changes after receiving your updated Identity Provider metadata.
Self-hosted Jama Connect
| Responsibility | Customer |
| Renew or activate the SAML signing certificate in the Identity Provider | √ |
| Export updated Identity Provider metadata | √ |
| Update the Jama Connect SAML configuration | √ |
| Validate authentication after the update | √ |
Resolution
Follow these steps to renew your SAML signing certificate.
Step 1: Renew the certificate in your Identity Provider
Your Identity Provider administrator should renew or replace the SAML signing certificate according to your organization's standard procedures.
Depending on your Identity Provider, this may include:
- Activating a new signing certificate
- Publishing updated federation metadata
- Exporting an updated Metadata XML file
- Obtaining the Identity Provider Metadata URL (preferred)
Refer to your Identity Provider documentation if you need assistance completing this step.
Step 2: Update Jama Connect
Cloud-hosted customers
After the certificate has been renewed, submit a Jama Support request and include:
- Your Jama Connect instance URL
- Whether the request is for a production or non-production environment
- Your preferred maintenance window (if applicable)
- Either:
- Your updated Metadata URL (preferred), or
- Your updated Metadata XML file
Jama Support will:
- Validate the updated metadata
- Update the SAML configuration for your Jama Connect instance
- Coordinate the maintenance window, if required
- Notify you when the update is complete and ready for testing
Self-hosted customers
After renewing the certificate in your Identity Provider, update the SAML configuration in your Jama Connect environment using the new Metadata URL or Metadata XML. Refer to the Self-hosted SAML administration documentation for detailed instructions.
Step 3: Validate authentication
After the update:
- Sign in using Single Sign-On.
- Verify that users can successfully authenticate.
- If electronic signatures use SAML authentication, verify that functionality as well.
- Report any authentication issues immediately.
Metadata URL vs. Metadata XML
Jama Connect supports two methods of receiving Identity Provider metadata.
Metadata URL (Recommended)
A Metadata URL allows Jama Connect to retrieve your Identity Provider metadata directly.
Benefits include:
- Simplifies future certificate updates
- Reduces manual configuration
- Lowers the risk of outdated certificate information
- Makes ongoing administration easier
Metadata XML
If your organization uses a Metadata XML file, a new XML file must be provided whenever the signing certificate changes so Jama Connect can be updated with the latest certificate.
Best Practices
To reduce the risk of authentication interruptions:
- Use a Metadata URL whenever your Identity Provider supports it.
- Monitor certificate expiration dates within your Identity Provider.
- Schedule certificate renewals before the certificate expires.
- Coordinate production updates during a planned maintenance window.
- Validate authentication immediately after the update.
- Retain a backup of your previous metadata until the update has been successfully validated.
Frequently Asked Questions
Will Jama renew my certificate?
No. The signing certificate is owned and managed by your organization's Identity Provider. Your Identity Provider administrator is responsible for renewing or replacing the certificate.
For Cloud-hosted environments, Jama Support updates the Jama Connect SAML configuration after you provide the updated Identity Provider metadata.
What does Jama Support do?
For Cloud-hosted customers, Jama Support manages the Jama Connect SAML configuration, updates your environment with the new Identity Provider metadata, coordinates the change, and assists with validation and troubleshooting.
How often will this happen?
Certificate lifetimes vary by Identity Provider and organizational policy. Many organizations renew signing certificates only every several years.
Will users experience downtime?
Most certificate renewals can be completed with little or no interruption when planned before the certificate expires. Jama Support will work with Cloud customers to coordinate the update and minimize any impact to users.
Additional Resources
- Success Programs
- Success Catalog
- Datasheets
- Request a Solution Offering or Training from the Success Catalog
Feedback:
We welcome your input! Please sign in to leave any comments, suggestions, or ideas for improvement below.
Comments
0 comments
Please sign in to leave a comment.