You can regenerate or renew the Omnissa Access self-signed SAML signing and encryption certificates when required. Typically, you regenerate certificates to address security issues, and renew certificates when they are about to expire. The option to renew certificates is available in Omnissa Access 24.12.1.0 and later.
-
Regenerating certicates: Regenerating a certificate creates a new certificate and generates new public and private keys. This immediately invalidates the old certificate, affecting all SAML integrations across your tenant. When you regenerate a certificate, you must update all SAML service provider and identity provider integrations with the new SAML metadata from Omnissa Access immediately. Until then, users will not be able to launch their web apps.
We recommend that you schedule regenerating certificates during a time that least impacts end users' access to their apps.
-
Renewing certificates: Renewing a certificate replaces the existing certificate with a new one that has an extended expiration date. The public and private keys remain unchanged. When you renew a certificate, you should update all your SAML service provider and identity provider integrations with the new SAML metadata from Omnissa Access as soon as possible. However, because the new certificate uses the same public and private keys as the old certificate, there is no disruption to end users in the meantime.
Note: The option to renew a certificate is available beginning with Omnissa Access version 24.12.1.0. In this version, renewing a certificate also updates the certificate to Omnissa branding. We strongly recommend that you renew the Omnissa Access certificates and update your SAML service provider and identity provider integrations at this time.
Note: This topic applies to Omnissa Access self-signed certificates only. If you use an external CA-signed certificate, create a new Certificate Signing Request in the Omnissa Access console and obtain a certificate from your CA.
Prerequisites
Take a snapshot of your Omnissa Access virtual appliance, connectors, and database before you update the SAML metadata.
Procedure
-
In the Omnissa Access console navigate to Resources > Web Apps.
-
Select Settings > SAML Metadata.
-
To renew or regenerate the signing certificate, click Renew or Regenerate in the Signing Certificate section.
Caution: When you regenerate a certificate, the old certificate is immediately invalidated and end users cannot log in to their apps until you update the third-party service provider or identity provider integration with the new Omnissa Access metadata.
-
To renew or regenerate the encryption certificate, click Renew or Regenerate in the Encryption Certificate section.
Caution: When you regenerate a certificate, the old certificate is immediately invalidated and end users cannot log in to their apps until you update the third-party service provider or identity provider integration with the new Omnissa Access metadata.
-
Update all your service provider and identity provider integrations with the new SAML metadata.
Was deze pagina nuttig?