Cisco Secure Access Help

PDF

Cisco Secure Access Help

Certificates for SAML Authentication

Want to summarize with AI?

Log in

Describes Certificates for SAML Authentication in Cisco Secure Access. Cisco Secure Access integrates with various Security Assertion Markup Language (SAML) identity providers (IdPs) that authenticate users.


Cisco Secure Access integrates with various Security Assertion Markup Language (SAML) identity providers (IdPs) that authenticate users. When a user requests a resource, Secure Access verifies the identity of the user through a trusted exchange with the integrated IdP and authorizes the user to get the resource. Users on devices must authenticate with Secure Access before connecting to private or web resources. The Secure Access services—Zero Trust (ZT), secure web gateway (SWG), and virtual private networks (VPNs)—must trust the connections from users and devices.

To set up a trust relationship between Secure Access (service provider) and an SAML IdP, an administrator imports the SAML IdP XML Metadata in to Secure Access, and then uploads the Secure Access XML Metadata to the SAML IdP's platform. The administrator adds the service provider's certificates to the IdP platform's trust store.

After you integrate an SAML IdP with Secure Access, you can manage the certificates in Secure Access for both the service provider (Secure Access) and your organization's IdPs. Secure Access lists a certificate's subject name, serial number, and expiration date and displays notifications about certificates that may expire.


Manage SAML Certificates for Service Providers

To establish a trust relationship between Cisco Secure Access (service provider) and an integrated SAML identity provider (IdP), certificates are exchanged between Secure Access and the SAML IdP. An administrator uploads the service provider's certificates from the Secure Access XML Metadata to the IdP platform's trust store. Then, an administrator imports the SAML IdP's XML Metadata that contains the IdP's certificates in to Secure Access.

After you integrate an SAML identity provider (IdP) in Secure Access, you can manage the service provider's certificates. Secure Access displays notifications about certificates that may expire. When the service provider certificates expire, an administrator must upload new certificates from the Secure Access XML Metadata to the integrated SAML IdP platform's trust store to prevent connection disruptions.

Secure Access manages the expiration of service provider certificates for various connection methods and SAML IdP integrations. Service provider certificates are used to establish the trust relationship between the service provider and the IdP. The IdP authenticates users that connect to Secure Access with:

  • Zero Trust (ZT)
  • Networks and network tunnels protected by Internet Security
  • Virtual Private Networks (VPNs) with a configured VPN profile
  • SSO Authentication for Secure Web Gateway and Zero Trust Access

Prerequisites


View Notifications About Expired Service Provider Certificates

Procedure

  1. Navigate to Secure > Certificates > SAML Authentication > Service Provider Certificates > Secure Web Gateway and Zero Trust Access.

  2. Secure Access displays any notifications about certificates that may expire.


    SAML Authentication page displaying options for Identity Provider Certificates and Service Provider Certificates

    See SAML Certificate Renewal Options for more information on how to renew.


Download Web Security and Zero Trust Service Provider Certificates

SSO Authentication: The service provider certificate is used by multiple IdP’s for SAML user authentication, and the certificate must be renewed yearly.

To set up the trust between Secure Access and the user devices in the organization that login via SSO, install a certificate on all devices and upload your organization's certificate to Secure Access. The certificate enables Secure Access to authenticate users and devices that connect via SSO.

Secure Web Gateway and Zero Trust Access table displays:

  • Subject name— The certificate's common name, which defines the entity that manages the certificate.
  • Serial number—The certificate serial number.
  • SSO Authentication—This shows multiple IdPs that are configured.
  • Certificate Type—shows if this is a signing certificate or encryption certificate.
  • Expiration date—The date when the certificate is no longer valid.

Procedure

  1. Navigate to Secure > Certificates > SAML integration > Service Provider Certificates > Secure Web Gateway and Zero Trust Access.

  2. Click Activate next to the new certificate to launch the activation modal.

  3. Next, click Download Signing Certificate to download the service provider certificate.

  4. Navigate to your IdP and update with the new certificate.

  5. Select the SSO authorization profile in the SSO Authentication list.

  6. Click Activate to confirm your choice.

    A notification appears once the certificate is activated.
  7. Verify that the new certificate is active in the Secure Web Gateway and Zero Trust Access list.


Download Virtual Private Network Service Provider Certificates

Procedure

  1. Navigate to Secure > Certificates > SAML Authentication > Service Provider Certificates.


    SAML Authentication page displaying options for Identity Provider Certificates and Service Provider Certificates
  2. For VPN Service Provider, click download on a certificate in the list to save the certificate to your local system. Then, upload the certificate to the SAML IdP.

    • Subject name—The certificate's common name, which defines the entity that manages the certificate.

    • Serial number—The serial number of the certificate.

    • Expiration date—The date when the certificate is no longer valid.


Manage SAML VPN Service Provider Certificate Rotation

Secure Access manages the expiration of service provider certificates for various connection methods and SAML IdP integrations. Service provider certificates are used to establish the trust relationship between the service provider and the IdP. The IdP authenticates users that connect to Secure Access with Virtual Private Networks (VPNs) with a configured VPN profile.

When Secure Access retires a service provider certificate, you need to rotate the service provider certificate used by your identity provider (IdP) to ensure admins and end users maintain successful access to applications.

Note

You must download the new Service Provider certificate, update your IdP with this new certificate, and activate the certificate within 24 hours before the current certificate expires. Failure to do this will result in SAML user authentication and connection failures.

Prerequisites

Procedure

  • View notifications about the expiration of Secure Access certificates that are deployed in SAML IdP integrations and VPN Profiles.

  • Identify those service provider certificates with pending expiration dates.


View Notifications About Expired Service Provider Certificates

Procedure

  1. Navigate to Secure > Certificates > SAML Authentication > Service Provider Certificates.


    SAML Authentication page displaying options for Identity Provider Certificates and Service Provider Certificates
  2. Secure Access displays any notifications about certificates that may expire. The certificate dashboard displays an alert icon next to certificates with a pending expiration date.


Activate a New VPN Service Provider Certificate

You must update your Identity Provider (IdP) with the new Service Provider certificate before making this certificate active. You cannot roll back to the old certificate.

Procedure

  1. Navigate to Secure > Certificates > SAML Authentication > Service Provider Certificates.


    SAML Authentication page displaying options for Identity Provider Certificates and Service Provider Certificates
  2. For the VPN Service Provider certificate, click Activate on the new certificate to launch the activation modal.


    VPN Service Provider page displaying options for serial number, and expiration date
  3. To activate a new VPN Service Provider certificate:


    Activate new Service Provider Certificate page displaying an option to activate new certificate
    1. Click the Download link to download the new VPN Service provider certificate.

    2. Update your IdP with this new certificate; see <xref href="../configure-integrations-with-saml-identity-providers/saml_certificate_renewal_options.xml" format="dita" scope="local">SAML Certificate Renewal Options</xref> for more information.

    3. Check the box that confirms you uploaded the new certificate to your IdP.

    4. Click Activate new certificate to confirm your choice.

      You must update your IdP before activating the certificate. Failure to do this will result in SAML user authentication and connection failures.


    Activate new Service Provider Certificate page displaying an option to activate new certificate
  4. Verify that the new certificate is Active in the VPN Service Provider certificates list.


    VPN Service Provider page displaying options for subject name, serial number, and expiration date

Manage SAML Certificates for Identity Providers

To establish a trust relationship between Cisco Secure Access (the service provider) and a SAML identity provider (IdP), you must exchange certificates between the two platforms. Import the Secure Access service provider certificates from the Secure Access XML metadata into the IdP trust store. Then, import the IdP XML metadata, which contains the IdP certificates, into Secure Access.

After you integrate an SAML identity provider (IdP) in Secure Access, you can manage the identity provider's certificates. Secure Access displays notifications about certificates that will expire. When the IdP certificates expire, an administrator must import new IdP certificates (XML Metadata) in Secure Access to prevent connection disruptions.

Secure Access manages the expiration of IdP certificates for various connection methods and SAML IdP integrations. IdP certificates are used to establish the trust relationship between the service provider and the IdP. The IdP authenticates users that connect to Secure Access with:

  • Zero Trust (ZT)

  • Networks and network tunnels protected by Internet Security

  • Virtual Private Networks (VPNs) with a configured VPN profile

  • SSO Authentication for Secure Web Gateway and Zero Trust Access

Before you begin

  • Ensure that your account has the Full Admin role in Secure Access. For more information, see Manage Accounts.

  • Ensure that Secure Access is integrated with a SAML identity provider (IdP). For more information, see Configure Integrations with SAML Identity Providers. If you use VPN authentication, see Manage Virtual Private Networks.

  • Ensure that IdP certificates use RSA 2048-bit (or larger) keys and SHA-256 (or stronger) signature algorithms. Secure Access does not support 1024-bit RSA keys or SHA-1 signatures.

Procedure

  1. Navigate to Secure > Certificates > SAML integration > Identity Provider certificates > Secure Web Gateway and Zero Trust Access.

    Note
    If any certificates are approaching expiration, Secure Access displays a warning banner at the top of the page.

    The SAML integration page with an expiration warning banner displayed above the certificate list
  2. Review the certificates.

    Secure Access uses these certificates to authenticate the certificates that your IdPs present.

    Table 1. Identity Provider certificate fields
    Field name Description
    Serial number The unique serial number of the certificate. The link opens a drawer to view additional certificate information.
    Issuer The Certificate Authority (CA) that issued the certificate. Includes the common name (CN), organization unit (OU), and country of origin (C).
    SSO Authentication The link brings you to the Configuration Management page for Users, Groups, and Endpoint Devices. You can upload the XML configuration file there. For more information, see Manage Users, Groups, and Endpoint Devices.
    IdP The name of the identity providers (IdPs) you are using.
    Expiration date The date when the certificate is no longer valid.