SSO Certificates Renewal
Action required before September 8th, 2026
This communication is intended for the teams responsible for SSO configuration. If you are not the appropriate contact, please forward this message to your IT department or SSO administrator.
Context
As part of ongoing industrywide security improvements, Certificate Authorities (CA) are significantly shortening the validity period of SSO certificates. Until recently, certificates were valid for 365 days. They now last only 200 days, and this duration will continue to decrease over the coming months—eventually dropping to less than two months.
1. If your organization uses its own certificates (not Esker certificates)
You have nothing to do.
Your SSO configuration is not based on Esker certificates.
2. If your organization uses Esker Federation Metadata URL
You have nothing to do.
Your SSO configuration already supports automatic certificate rollover, which is now the recommended approach from major identity providers (Microsoft Entra ID, Okta, Ping Identity).
- Certificate renewals are fully automatic.
- No action is required for this renewal or future ones.
3. If your organization manually updates Esker certificates
Action Required Before September 8th, 2026
(Only for organizations still using manual SSO certificate xml uploads)
Your Esker on Demand environment will renew its SSO certificates as part of routine security maintenance.
If your SSO configuration relies on manual certificate uploads, you must install the new certificate before September 8th, 2026 to avoid service disruption.
- On August 10th, 2026, Esker will set the new certificate as primary and the current one as secondary.
- If the new certificate is not uploaded by September 8th, 2026, SSO authentication will fail, and users will be unable to sign in.
- Token Encryption: sso.7.crypt.esker.com
- Token Signing: sso.7.sign.esker.com
If you are not the SSO administrator, please forward this message to the appropriate team in your organization.
Procedure to install the new certificate:
There are two new certificates, both issued by DigiCert
They are available for download here:
https://doc.esker.com/Download.asp?file=SSO/SSO_Tower_K_cert.zip
Preparing for the future – Recommended transition to automatic rollover
Because certificate validity periods are decreasing so rapidly, all organizations using manual SSO configurations will need to transition to Federation Metadata.
- Manual certificate updates will become increasingly operationally risky.
- Your organization must plan the transition before the next SSO certificate expiration in March 2027 by:
- Using your own certificates instead of Esker's, or
- Automatically retrieving Esker certificates using the Federation Metadata URL.
https://ne7.ondemand.esker.com/FederationMetadata/2007-06/FederationMetadata.xml
- As with industry best practices, for customers who continue using manual configurations, please ensure that your teams have a clear internal process to track certificate expiry and retrieve updated certificates from Esker when needed, as Esker will no longer send routine certificate‑renewal notifications.
If you have any questions on transitioning to automatic rollover, please contact your IT service.