Skip to main content

July 1, 2026

Enabling Common Service Provider Metadata in Connection Servers

You can enable usage of common metadata across the cluster using the LDAP flag pae-SAMLKeySharingEnabled.

Note: Setting this flag doesn’t require restart of any service.

Prerequisites

Procedure

  1. Log in to the pod’s Connection Server with domain administrator privileges.

  2. Open the ADSI Edit tool (from Windows Administrative Tools).

  3. In the console tree, select Connect to.

  4. In the Select or type a Distinguished Name or Naming Context text box, enter the distinguished name.

  5. In the Computer pane, select or type localhost:389 or the fully qualified domain name (FQDN) of the Connection Server host followed by port 389.

    For example: localhost:389 or mycomputer.example.com:389

  6. Expand the ADSI Edit tree, then expand OU=Properties.

  7. Select OU=Global, and double-click CN=Common in the right pane.

  8. In the Properties dialog box, set the pae-SAMLKeySharingEnabled attribute to 1.

  9. When the common metadata feature is enabled, launching sp.xml from any Connection Server in the cluster using this URL will result in the same signing and encryption credentials:

    https://<CS_FQDN>/SAML/metadata/sp.xml

  10. If WS1 Access is used, please perform a sync of the Virtual App Collection on the Access side.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…