Manage IdP metadata for a 1:1 connection

Update an IdP metadata certificate

The certificates for additional identity providers must be kept up to date to avoid access issues. When a certificate that belongs to one of your additional identity providers is due to expire:

  1. Go to Keystone settings > 1:1 connections.

  2. Find the entity you want to update in the list.

  3. From the Options menu, select Update metadata.

    Options menu for an entity called 'Hard Science Publishing' expanded to show the options 'Update metadata' (which is highlighted), 'Rename' and 'Delete'.
  4. Enter and confirm the new metadata URL or metadata file in the same way as when adding a 1:1 connection.

View IdP metadata

If you need to check details of the SAML metadata uploaded for the IdP, you can view the current metadata.

  1. Go to Keystone settings > 1:1 connections.

  2. Find the entity in your list of additional identity providers.

  3. From the Options menu, select View SAML metadata.

    Options menu for a connection called 'Acme Journals'. The menu is open to show the options 'View SAML metadata', 'Update metadata', 'Rename' and 'Delete'.
  4. The metadata displays in a pop-up window.

    Pop-up window titled 'Acme Journals - This view displays the SAML metadata of this organization.' The entityID is followed by the full 'Identity Provider SAML metadata' certificate in XML. There are controls labeled 'Copy to clipboard', 'Close' and 'Update metadata'.
  5. To copy the metadata, click Copy to clipboard.

  6. If you need to upload new metadata for the IdP, press Update metadata. Enter and confirm the new metadata URL or metadata file in the same way as when adding a 1:1 connection. (You can also do this directly from the list of connections. See Update an IdP metadata certificate.)

  7. To close the pop-up window, press Close.