Skip to content

Remove recommendation for CA-signed certificates#615

Open
monfresh wants to merge 1 commit into
mainfrom
no-ca-certs
Open

Remove recommendation for CA-signed certificates#615
monfresh wants to merge 1 commit into
mainfrom
no-ca-certs

Conversation

@monfresh
Copy link
Copy Markdown
Contributor

After internal discussion and internet research, we could not find compelling evidence to support our existing recommendation for CA-signed certificates for production integrations. However, we found a few sources stating that self-signed certificates are perfectly acceptable in the context of signing SAML or OIDC requests.

References:

After internal discussion and internet research, we could not find compelling evidence to support our existing recommendation for CA-signed certificates for production integrations. However, we found a few sources stating that self-signed certificates are perfectly acceptable in the context of signing SAML or OIDC requests.

References:

- https://workos.com/blog/ca-signed-certificates-saml
- https://support.pingidentity.com/s/article/Do-I-need-a-trusted-CA-signed-certificate-for-SAML-signatures
- https://knowledge.exlibrisgroup.com/Alma/Knowledge_Articles/Benefits_and_Recommendations_for_Long-Term_Self-Signed_SAML_Certificates
- The SAML spec: https://docs.oasis-open.org/security/saml/Post2.0/sstc-metadata-iop-os.pdf
@monfresh monfresh requested a review from mmagsa May 15, 2026 22:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant