|
68 | 68 | <h3 id="set-up" style="position:relative;"><a href="#set-up" aria-label="set up permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Set Up</h3>
|
69 | 69 | <p>To configure Single Sign-On via SAML:</p>
|
70 | 70 | <ol>
|
71 |
| -<li>Go to: <strong>Program Settings > General > Authentication</strong>.</li> |
| 71 | +<li>Go to <strong>Program Settings > General > Authentication</strong>.</li> |
72 | 72 | <li>Click <strong>Setup SAML</strong> in the <em>Single Sign-on with SAML</em> section.</li>
|
73 | 73 | </ol>
|
74 | 74 | <p><span
|
@@ -309,7 +309,97 @@ <h3 id="additional-information" style="position:relative;"><a href="#additional-
|
309 | 309 | style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"
|
310 | 310 | loading="lazy"
|
311 | 311 | />
|
312 |
| - </span></p></div><div class="footer__inner"><div class="footer-row"><div class="footer-column footer-column--left"><div class="footer-column-block"><a href="https://github.com/Hacker0x01/docs.hackerone.com/edit/master/docs/programs/single-sign-on-sso-via-saml.md">Edit this page on GitHub</a></div></div><div class="footer-column footer-column--center"><div class="footer-column-block"><span>Was this article helpful?<!-- --> <a href="" class="upvote upvote--up">👍</a> <a href="" class="upvote upvote--down">👎</a></span></div></div><div class="footer-column footer-column--right"><div class="footer-column-block"><a href="https://www.hackerone.com" target="_blank">Back to HackerOne</a></div></div></div></div></article><div class="toc"><div class="toc-wrapper"><div class="sidebar__body"><div class="sidebar__section"><h3 class="sidebar__title sidebar__title--active">On this page</h3><ul class="sidebar__items sidebar__items--active"><li class="sidebar__item"><a href="#set-up">Set Up</a></li><li class="sidebar__item"><a href="#additional-information">Additional Information</a></li></ul></div></div></div></div></div></div></div></div><div id="gatsby-announcer" style="position:absolute;top:0;width:1px;height:1px;padding:0;overflow:hidden;clip:rect(0, 0, 0, 0);white-space:nowrap;border:0" aria-live="assertive" aria-atomic="true"></div></div><script> |
| 312 | + </span></p> |
| 313 | +<h3 id="configure-an-alternative-certificate" style="position:relative;"><a href="#configure-an-alternative-certificate" aria-label="configure an alternative certificate permalink" class="anchor before"><svg aria-hidden="true" focusable="false" height="16" version="1.1" viewBox="0 0 16 16" width="16"><path fill-rule="evenodd" d="M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z"></path></svg></a>Configure an Alternative Certificate</h3> |
| 314 | +<p>If you need to switch your identity provider or if your current SAML certificate is expiring, you can configure an alternative SAML certificate to avoid having to disable your SSO integration during the update.</p> |
| 315 | +<blockquote> |
| 316 | +<p><strong>Note:</strong> Only the admin of the program has the ability to configure the alternative certificate.</p> |
| 317 | +</blockquote> |
| 318 | +<p>To configure an alternative certificate:</p> |
| 319 | +<ol> |
| 320 | +<li>Go to <strong>Program Settings > General > Authentication</strong>.</li> |
| 321 | +<li>Click <strong>configure</strong> next to <strong>X509 alternative certificate</strong>.</li> |
| 322 | +</ol> |
| 323 | +<p><span |
| 324 | + class="gatsby-resp-image-wrapper" |
| 325 | + style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 500px; " |
| 326 | + > |
| 327 | + <span |
| 328 | + class="gatsby-resp-image-background-image" |
| 329 | + style="padding-bottom: 53.6%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAABYlAAAWJQFJUiTwAAAA70lEQVQoz52Si66DIAyGef/HdPOG84LjIqL+p+2OiVu2xK3JZ5XgR4GqoiiQ5znKspSstYYxRnDOwVl7Hpqv6roG0zSNyPi9qir55gn2H3cCS1LV3Fq0bYcb0XY9pjgLYYrwYfoKa6lC7z3mlDDPSfKyrMTyyOtJaO5KmV1K0xb3knlg2zb8GoGFxzOLMYrwFzj8LmT4Qvq+l9KP8a7ifeytkNuFybIM1+tFLqcj8TAMT/BiDB/Nq+xJyNtlepHQT2OEsYtU+omj8Bgi5Af3z+tWz8Y6Biz1iO0+UasFqH2lR6t8Txqp7bRBugfqRY8/5F9Z+Q79ThMAAAAASUVORK5CYII='); background-size: cover; display: block;" |
| 330 | + ></span> |
| 331 | + <img |
| 332 | + class="gatsby-resp-image-image" |
| 333 | + alt="Authentication settings page with SAML configured" |
| 334 | + title="Authentication settings page with SAML configured" |
| 335 | + src="/static/402c7d92023dd2341b2ea6d06c9fc8dd/0b533/alt-certificate-1.png" |
| 336 | + srcset="/static/402c7d92023dd2341b2ea6d06c9fc8dd/fac75/alt-certificate-1.png 125w, |
| 337 | +/static/402c7d92023dd2341b2ea6d06c9fc8dd/63868/alt-certificate-1.png 250w, |
| 338 | +/static/402c7d92023dd2341b2ea6d06c9fc8dd/0b533/alt-certificate-1.png 500w, |
| 339 | +/static/402c7d92023dd2341b2ea6d06c9fc8dd/1d69c/alt-certificate-1.png 750w, |
| 340 | +/static/402c7d92023dd2341b2ea6d06c9fc8dd/00d43/alt-certificate-1.png 1000w, |
| 341 | +/static/402c7d92023dd2341b2ea6d06c9fc8dd/29beb/alt-certificate-1.png 1830w" |
| 342 | + sizes="(max-width: 500px) 100vw, 500px" |
| 343 | + style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;" |
| 344 | + loading="lazy" |
| 345 | + /> |
| 346 | + </span></p> |
| 347 | +<ol start="3"> |
| 348 | +<li>Enter the alternative certificate in the <strong>Configure alternative certificate</strong> window. </li> |
| 349 | +</ol> |
| 350 | +<p><span |
| 351 | + class="gatsby-resp-image-wrapper" |
| 352 | + style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 500px; " |
| 353 | + > |
| 354 | + <span |
| 355 | + class="gatsby-resp-image-background-image" |
| 356 | + style="padding-bottom: 92%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAASCAYAAABb0P4QAAAACXBIWXMAABYlAAAWJQFJUiTwAAACwUlEQVQ4y6WUy24aQRBF+Y98W7aRnPxAvsPYMSxiKdvsHMQujLHlRbLKJpGCAfMamPfAMC/GGG5u1QC2V06Uka6qu6v7dFV191TevX2H84/nqJ3VUK/VUauVdt9W0Xf24Qwn1RMcHx+jWq3i9OT0IBmv1+s4OjpC5eLiAvJ5noflcok0TRFFkSpJEuR5jvl8rnrpa3xpoGIYhkKGwyEmkwksy8LENDGbzWDZtlqT/eFwBN/3ddPFotwwjmNVGIYKvL6+LoGrPMN4PIJtEUI5BNm2pdbkJjEhRbFixDFSRi06tNOE0KUCr9ptVFotAxt25nGBKLmn1lim64NN8g1Wa6iKh+da7WxWQBnGpQIvtROxRp7jIvB8uLaj7Wi+QBqzjmmmypIUGcsjkUlbxsS/Yp3la7UESOr6fgt70IczGqpmd4/tab8HeziANxnDGtyppC9zpD2jf+E5CvzK4CotowTOerewZPFdOWna62rf4WJbIAKQ/oCwXo+in2OTzm+ErHcJ3KUsQKvfhSuR8HAE4giEcnn6AhGfQP2dX+AyNu3eYuHYZcrGPuViS0dHIdNuV6OTKGWRLNDI5UqNxwoTkEQnG8kme6BxebVLmSc4kwg5IWAE7m6RJ5GyBD5BUkPfnOim6hcrWXCzyHWeAx94zHIAUmxXUmJbLdMVkKNjZaourT814fMBBIzMpX9/KAo0CLyXCBlFMJ0e0tE0d3U0Ox2Yt/tD66tmcjiES3lCPobHCHc1tFgrnxMC7ugxwjl3zxa8h/Km+bRS3tOMbbFJEKhN5yGWnos8jp6mXF7sMArgBx5cpiKS91kU99hsNi/+FLbb7VMgn55TYPnTRjJaIOcVygvRBvlqg+wvlOZrCLLdJvCKf4jVm8+YvHqP8PUn/M93c3ODSqPRgPejh2HzO8xvv2A78qf5N8kvTkrUbDbxB16OJbsgUfYBAAAAAElFTkSuQmCC'); background-size: cover; display: block;" |
| 357 | + ></span> |
| 358 | + <img |
| 359 | + class="gatsby-resp-image-image" |
| 360 | + alt="configure alternative certificate modal " |
| 361 | + title="configure alternative certificate modal " |
| 362 | + src="/static/318948a2315ad25bb3eb4664468c44a0/0b533/alt-certificate-2.png" |
| 363 | + srcset="/static/318948a2315ad25bb3eb4664468c44a0/fac75/alt-certificate-2.png 125w, |
| 364 | +/static/318948a2315ad25bb3eb4664468c44a0/63868/alt-certificate-2.png 250w, |
| 365 | +/static/318948a2315ad25bb3eb4664468c44a0/0b533/alt-certificate-2.png 500w, |
| 366 | +/static/318948a2315ad25bb3eb4664468c44a0/1d69c/alt-certificate-2.png 750w, |
| 367 | +/static/318948a2315ad25bb3eb4664468c44a0/00d43/alt-certificate-2.png 1000w, |
| 368 | +/static/318948a2315ad25bb3eb4664468c44a0/3d405/alt-certificate-2.png 1348w" |
| 369 | + sizes="(max-width: 500px) 100vw, 500px" |
| 370 | + style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;" |
| 371 | + loading="lazy" |
| 372 | + /> |
| 373 | + </span></p> |
| 374 | +<ol start="4"> |
| 375 | +<li>Click <strong>Save</strong>.</li> |
| 376 | +</ol> |
| 377 | +<p>After the alternative certificate has been configured, users will be able to authenticate through the new SAML certificate.</p> |
| 378 | +<p>When the primary certificate isn't used anymore, you can promote the alternative certificate to the primary by clicking <strong>Promote alternative certificate to primary certificate</strong>. This will enable your primary certificate to be replaced with the alternative. </p> |
| 379 | +<p><span |
| 380 | + class="gatsby-resp-image-wrapper" |
| 381 | + style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 500px; " |
| 382 | + > |
| 383 | + <span |
| 384 | + class="gatsby-resp-image-background-image" |
| 385 | + style="padding-bottom: 58.4%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAMCAYAAABiDJ37AAAACXBIWXMAABYlAAAWJQFJUiTwAAABDklEQVQoz52Si46DIBBF/f/fNAoY3/JSxLszWG1rdremJCcDaE5guFlZliiKAkKIVKuqwjAMCWMMoWG03utHDDIpJRgWMa/rXXgfrUlY1w3qpk00bQc/L3B+TljnCH+D/T/NJzTWYlmWBwHruiIQayLeJ0Y4Emd8NUtSPjLXjT58O7z3yJRSZ894Y9u2rziFx2MwXdch3jjhIbiuk5CjckQnz3O09DBHbPpHHcfx3Jum6ZQcojehlAKKUZIQkFUHVU/UT+ppioJ+gxt/Ci/iJBQkKGWLQjQQiuaErPqTZ8Z+EV6unoRu3mBchPVP3Mv804ijw1r22HoHT1nMYlzxHyGEv6GsLpPF3EwIVDl2PxElpczNXkRqAAAAAElFTkSuQmCC'); background-size: cover; display: block;" |
| 386 | + ></span> |
| 387 | + <img |
| 388 | + class="gatsby-resp-image-image" |
| 389 | + alt="authentication settings page with alt certificate configured" |
| 390 | + title="authentication settings page with alt certificate configured" |
| 391 | + src="/static/8a75a2dca10e935c163b6420129b902d/0b533/alt-certificate-3.png" |
| 392 | + srcset="/static/8a75a2dca10e935c163b6420129b902d/fac75/alt-certificate-3.png 125w, |
| 393 | +/static/8a75a2dca10e935c163b6420129b902d/63868/alt-certificate-3.png 250w, |
| 394 | +/static/8a75a2dca10e935c163b6420129b902d/0b533/alt-certificate-3.png 500w, |
| 395 | +/static/8a75a2dca10e935c163b6420129b902d/1d69c/alt-certificate-3.png 750w, |
| 396 | +/static/8a75a2dca10e935c163b6420129b902d/00d43/alt-certificate-3.png 1000w, |
| 397 | +/static/8a75a2dca10e935c163b6420129b902d/bcec6/alt-certificate-3.png 1834w" |
| 398 | + sizes="(max-width: 500px) 100vw, 500px" |
| 399 | + style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;" |
| 400 | + loading="lazy" |
| 401 | + /> |
| 402 | + </span></p></div><div class="footer__inner"><div class="footer-row"><div class="footer-column footer-column--left"><div class="footer-column-block"><a href="https://github.com/Hacker0x01/docs.hackerone.com/edit/master/docs/programs/single-sign-on-sso-via-saml.md">Edit this page on GitHub</a></div></div><div class="footer-column footer-column--center"><div class="footer-column-block"><span>Was this article helpful?<!-- --> <a href="" class="upvote upvote--up">👍</a> <a href="" class="upvote upvote--down">👎</a></span></div></div><div class="footer-column footer-column--right"><div class="footer-column-block"><a href="https://www.hackerone.com" target="_blank">Back to HackerOne</a></div></div></div></div></article><div class="toc"><div class="toc-wrapper"><div class="sidebar__body"><div class="sidebar__section"><h3 class="sidebar__title sidebar__title--active">On this page</h3><ul class="sidebar__items sidebar__items--active"><li class="sidebar__item"><a href="#set-up">Set Up</a></li><li class="sidebar__item"><a href="#additional-information">Additional Information</a></li><li class="sidebar__item"><a href="#configure-an-alternative-certificate">Configure an Alternative Certificate</a></li></ul></div></div></div></div></div></div></div></div><div id="gatsby-announcer" style="position:absolute;top:0;width:1px;height:1px;padding:0;overflow:hidden;clip:rect(0, 0, 0, 0);white-space:nowrap;border:0" aria-live="assertive" aria-atomic="true"></div></div><script> |
313 | 403 |
|
314 | 404 | function gaOptout(){document.cookie=disableStr+'=true; expires=Thu, 31 Dec 2099 23:59:59 UTC;path=/',window[disableStr]=!0}var gaProperty='UA-49905813-10',disableStr='ga-disable-'+gaProperty;document.cookie.indexOf(disableStr+'=true')>-1&&(window[disableStr]=!0);
|
315 | 405 | if(!(parseInt(navigator.doNotTrack) === 1 || parseInt(window.doNotTrack) === 1 || parseInt(navigator.msDoNotTrack) === 1 || navigator.doNotTrack === "yes")) {
|
|
0 commit comments