Skip to main content

SSO Certificates Renewal

Action required before September 8th, 2026

This communication is intended for the teams responsible for SSO configuration. If you are not the appropriate contact, please forward this message to your IT department or SSO administrator. 

 
Context 
As part of ongoing industrywide security improvements, Certificate Authorities (CA) are significantly shortening the validity period of SSO certificates. Until recently, certificates were valid for 365 days. They now last only 200 days, and this duration will continue to decrease over the coming months—eventually dropping to less than two months

 
1. If your organization uses its own certificates (not Esker certificates) 

You have nothing to do. 

Your SSO configuration is not based on Esker certificates. 

 
2. If your organization uses Esker Federation Metadata URL 

You have nothing to do. 

Your SSO configuration already supports automatic certificate rollover, which is now the recommended approach from major identity providers (Microsoft Entra ID, Okta, Ping Identity). 

  • Certificate renewals are fully automatic.
  • No action is required for this renewal or future ones. 

 
3. If your organization manually updates Esker certificates 

Action Required Before September 8th, 2026 

(Only for organizations still using manual SSO certificate xml uploads) 

Your Esker on Demand environment will renew its SSO certificates as part of routine security maintenance. 

If your SSO configuration relies on manual certificate uploads, you must install the new certificate before September 8th, 2026 to avoid service disruption. 

  • On August 10th, 2026, Esker will set the new certificate as primary and the current one as secondary.
  • If the new certificate is not uploaded by September 8th, 2026, SSO authentication will fail, and users will be unable to sign in.
  • Token Encryption: sso.7.crypt.esker.com
  • Token Signing: sso.7.sign.esker.com 

If you are not the SSO administrator, please forward this message to the appropriate team in your organization. 

 
Procedure to install the new certificate: 

There are two new certificates, both issued by DigiCert 

They are available for download here:  

https://doc.esker.com/Download.asp?file=SSO/SSO_Tower_K_cert.zip 

 
Preparing for the future – Recommended transition to automatic rollover 

Because certificate validity periods are decreasing so rapidly, all organizations using manual SSO configurations will need to transition to Federation Metadata. 

  • Manual certificate updates will become increasingly operationally risky.
  • Your organization must plan the transition before the next SSO certificate expiration in March 2027 by:
  • Using your own certificates instead of Esker's, or
  • Automatically retrieving Esker certificates using the Federation Metadata URL

https://ne7.ondemand.esker.com/FederationMetadata/2007-06/FederationMetadata.xml 

  • As with industry best practices, for customers who continue using manual configurations, please ensure that your teams have a clear internal process to track certificate expiry and retrieve updated certificates from Esker when needed, as Esker will no longer send routine certificaterenewal notifications

If you have any questions on transitioning to automatic rollover, please contact your IT service.

Top