What is this about?
If your SSO is connected to Microsoft Entra (Azure AD) via the app federation metadata URL, you do not need to send us anything when the certificate changes. The current SAML signing certificate is automatically retrieved via the stored metadata URL.
What is the App Federation Metadata URL?
The App Federation Metadata URL is the public metadata link for your Entra SAML app (Enterprise App → Single Sign-on → SAML). It contains, among other things, the signing certificates. softgarden uses this URL to automatically retrieve the valid certificates.
What happens during a certificate rotation?
You rotate the SAML signing certificate in Entra (add/activate the new certificate, while keeping the old one valid briefly in parallel).
The metadata URL publishes the new certificate.
softgarden automatically detects the new certificate via the configured URL.
What do you need to do?
Use only the metadata URL (do not upload the certificate manually).
When switching, activate the new certificate and keep the old one valid briefly in parallel → ensures a seamless transition.
Test the login (e.g., in a private browser window). If the login works, everything is set up correctly.
When should you still notify us?
If you are not connected via the metadata URL (i.e., a manual certificate file is stored). → Please switch to using the metadata URL.
If the metadata URL is not publicly accessible (e.g., due to a WAF or firewall). → Please enable access.
If you deactivated the old certificate immediately and are experiencing login errors. → Contact technical support; we will then check the metadata.
