Using self-signed certificates single-sign-on (SSO)

When you configure SAML Single Sign-On (SSO) in Zoom, you can manage one or more Service Provider (SP) certificates and choose which one is currently active. These SP certificates, including Zoom-provided and self-signed ones, are used by Zoom to:

If any of these options is enabled in your SSO configuration, the SP certificate configured on your Identity Provider (IdP) must match the certificate that is currently active in Zoom. Otherwise, signature validation or assertion decryption will fail and SSO login will not work.

This article explains how to add, view, switch, and delete self-signed SP certificates, and provides common troubleshooting steps.

Requirements for using self-signed certificates for single-sign-on (SSO)

Table of Contents

Recommended configuration for self-signed service provider certificates

note icon
These recommendations are provided for general guidance only and do not constitute legal or security advice. Organizations should consult their own security and compliance teams.
 
FieldRecommended valueNotes
Key size2048 bitRecommended unless you have a specific compliance or security requirement that mandates a larger key.
Expiration periodChoose based on your internal security policyA longer validity period reduces how often you need to rotate the certificate, but it also extends the exposure window if the key is ever compromised.

How to add a self-signed service provider certificate

To add a new self-signed certificate:

  1. Sign in to the Zoom web portal as an admin.
  2. In the top-right corner, click your profile picture or initials, then click Admin Center.
  3. In the side menu, click Security and trust.
  4. Click Single Sign-On.
  5. Click Edit.
    Note: If you utilize multiple SSO configurations, next to the desired configuration, click Edit.
  6. Next to the Service provider (SP) certificate section, click Add.
    Note: This option will only be available if Sign SAML request, Sign SAML Logout request, or Support encrypted assertions has been enabled.
  7. In the Add SP certificate window, fill in the following fields:
  8. (Optional) Click the Directly use this certificate checkbox to make the certificate the active certificate.
    Note: If this option is not enabled, while the certificate will be added, it will not be the active certificate.
  9. Click Save.
    The Add SP certificate window will close.
  10. (Optional) Review and download the certificate if necessary.
  11. At the bottom of the Configure SSO page, click Save.

How to manage self-signed service provider certificates

View a self-signed certificate’s details

To view the details for your self-signed certificate:

  1. Sign in to the Zoom web portal as an admin.
  2. In the top-right corner, click your profile picture or initials, then click Admin Center.
  3. In the side menu, click Security and trust.
  4. Click Single Sign-On.
  5. Click Edit.
  6. Click the Service provider (SP) certificate dropdown.
  7. Next to the desired certificate, click View details.
    The certificate's details will be displayed, including the following:
  8. (Optional) Next to Certificate, click one of the following options:

Switch the active self-signed certificate

To switch the current active certificate:

  1. Sign in to the Zoom web portal as an admin.
  2. In the top-right corner, click your profile picture or initials, then click Admin Center.
  3. In the side menu, click Security and trust.
  4. Click Single Sign-On.
  5. Click Edit.
  6. Click the Service provider (SP) certificate dropdown.
  7. Select the desired certificate.
  8. At the bottom of the Configure SSO page, click Save.

Once the certificate is active, you will need to refresh the SP metadata or update the SP certificate on your IdP to align with the active Zoom certificate. To confirm the update was successful, perform a test SSO login. Failure to update these settings on your IdP can result in SSO login errors.

Delete a self-signed certificate

Note: A certificate can not be deleted if it is the active certificate. If the certificate is active, a new or different existing certificate will need to be set as the active certificate.

To delete a self-signed certificate:

  1. Sign in to the Zoom web portal as an admin.
  2. In the top-right corner, click your profile picture or initials, then click Admin Center.
  3. In the side menu, click Security and trust.
  4. Click Single Sign-On.
  5. Click Edit.
  6. Click the Service provider (SP) certificate dropdown.
  7. Next to the desired certificate, click View details.
    The certificate's details will be displayed.
  8. At the bottom of the Certificate details window, click Delete.
  9. When prompted for confirmation, click Delete.
    The certificate will be deleted.

How to troubleshoot issues with self-signed service provider certificates

Unable to add certificates

If you are unable to add new certificates, do the following:

SSO login fails right after switching certificates

The most common cause of being unable to switch certificates is that the IdP is still configured with the previous certificate. To resolve this issue:

  1. Confirm that the IdP is using the same certificate that is currently active in Zoom by doing the following:
  2. Test logging in with SSO again.