Skip to content

Login.gov 2026 SAML certificate rotation #5789

@FuhuXia

Description

@FuhuXia

Annual Login.gov SAML certificate rotation needs to be done by March 2026. The 2025 certificates expire on April 1, 2026.

Sketch

Follow steps describe in wiki Login.gov SAML certificate rotation steps and notes from previous year.

  • Generate new SP certificates.

The following two steps should be done at about the same time to minimize app authentication down time.

  • Update development IdP metadata URL in the code, update private keys in the CF environment.
  • Update public certs for development apps in login.gov sandbox dashboard.

The following two steps should be done at about the same time to minimize app authentication down time.

  • Update staging and prod IdP metadata URL in the code, update private keys in the CF environment.
  • Update public certs for staging/prod in the mirrored apps in login.gov sandbox dashboard, submit change requests to have the mirrored apps promoted, make sure they are deployed.

Metadata

Metadata

Assignees

Labels

bugSoftware defect or bug

Type

No type

Projects

Status

🏗 In Progress [8]

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions