Action required before January 25: Applications using Michigan Medicine SSO (SAML) Identity Provider Service

01/24/2023

The Production IdP Signing certificate for the Michigan Medicine Web SSO (SAML) / Access Manager / Web login authentication service will be replaced on January 25 between 5:00 p.m. to 5:30 p.m. and the SAML metadata will be refreshed with the new signing cert info.

Failure to update the IdP cert in your SP configuration will result in authentication errors for your application after our cert change on Jan 25, 2023.

We will be following the same process that we did for weblogin.med.umich.edu IdP cert change last year.

Please review the 2023 Michigan Medicine SAML SSO / Access Manager / Web login Certificate Expiration -  KB0018287  to understand more about this process and the action required on your end as a Service Provider.

Monday, January 23–Receive the new pem cert to prepare for the change

Wednesday, January 25, 5:00 p.m. – 5:30 p.m. (IAM change window)

Wednesday, January 25, 5:30 p.m. – 7:00 p.m. (SP change window)

What to do if login is NOT successful after you update the cert on January 25

Rollback requests 

Questions / Concerns - Service Now Tickets to IAM

Additional Support

FAQs

Important Resources

2023 Michigan Medicine SAML SSO / Access Manager / Web login Certificate Expiration -  KB0018287

CHG0151442- Update of Signing certificate for Michigan Medicine SAML Identity Provider (weblogin.med.umich.edu)

Web SSO (SAML) Configuration Primer