The Tuakiri Hosted IdP runs a SAML Identity Provider (IdP) as a SAML proxy, facing Tuakiri as an IdP and facing an upstream IdP as a Service Provider (SP).
The upstream IdP of the Tuakiri Hosted IdP instance may be Microsoft Entra ID. The certificate included in the metadata produced by Microsoft Entra ID has a fixed expiry date (usually 3 years) and would stop functioning at the expiry time (and the metadata itself would expire as well).
Before the certificate and the metadata expire, it is necessary to replace the certificate, create new metadata, and replace it on the Tuakiri Hosted IdP instance.
This page documents the steps required to replace the certificate and update the metadata for the Entra ID registration of a Tuakiri Hosted IdP instance.
Tuakiri Login
).
tuakiri
into the search box (Search by application name
)Manage
=>
Single sign-on
=>
SAML Certificates
, select Edit
, New Certificate
, and Save
.
SAML Signing Certificate
pop up (by clicking the X
in the top-right corner)SAML Certificates
panel, Download
the Federation Metadata XML
.
Only after receiving confirmation the metadata has been updated on Tuakiri Hosted IdP, proceed with the following steps (again, repeating them for both TEST and PROD instances of your application).
Manage
=>
Single sign-on
=>
SAML Certificates
, again select Edit
...
at the end of the line representing the certificate), select Make certificate active
). The previously Active certificate will now become Inactive.
Expiration Date
should also help tell the the old and new certificates apart.Delete Certificate
from its ...
context menu).
SAML Signing Certificates
popup.Download
the Federation Metadata XML
once more and send to tuakiri@reannz.co.nz.