Why Does the Browser Certificate Expiration Date Stay the Same After a SAML Certificate Rotation?

Carmen Santos
Carmen Santos
  • Updated
  • Jama Connect® - All Versions
    • Cloud/CVC
    • Self-hosted
  • SSO using SAML 2.0

Summary

After rotating the Security Assertion Markup Language (SAML) signing certificate used for single sign-on, the certificate expiration date displayed in the browser does not change.

This behavior is expected because the SAML signing certificate and the browser’s TLS/SSL certificate are separate certificates with different purposes:

  • The SAML signing certificate validates authentication messages exchanged between Jama Connect and an identity provider (IdP), such as Microsoft Entra ID.
  • The TLS/SSL certificate secures the HTTPS connection between the browser and the Jama Connect URL. This is the certificate displayed in the browser.

In the example shown below, the browser certificate was issued by Amazon. Because the TLS/SSL and SAML certificates are managed independently, rotating the SAML signing certificate does not change the browser certificate or its expiration date.

Resolution

Review the browser certificate

Step 1: Open the Jama Connect URL.

Step 2: Select the site information or security icon in the browser’s address bar.

Step 3. Open the certificate details and review the issuer, validity period, and expiration date.

The expiration date displayed in the browser applies only to the website’s TLS/SSL certificate. It does not indicate the status or expiration date of the SAML signing certificate.

Address certificate-related issues

  • If SSO works and the browser reports a secure connection, no action is required.
  • If SSO stops working after the SAML certificate rotation, confirm that Jama Connect and the identity provider are configured with the correct, current SAML certificate.
  • If the browser reports an insecure connection or an expired TLS/SSL certificate, contact your Jama Connect administrator or Jama Software Support. Include the following information:
    • The Jama Connect URL
    • The complete browser error message
    • The certificate issuer, validity period, and expiration date

Additional Resources 

Feedback:
We welcome your input! Please sign in to leave any comments, suggestions, or ideas for improvement below.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment.