2026 Certificate Support
Do I need to take action on the Certificate change?
- If your SAML identity provider implementation verifies authentication request signatures, you will need to update your SAML configuration to use the new certificate.
- If you are unsure whether your implementation is configured to verify SAML request signatures, we recommend checking your IdP settings as soon as possible to determine whether this update is required.
- If you do need to make the update, but are unable to make the change at the required time, you may consider temporarily disabling SAML request signature checking before the the new certificate is deployed in IBMid, and then re-enabling at a later time.
- To avoid disruption, ensure your Identity Provider technical team installs the new IBMid signing certificate at the scheduled time. Not taking this action may prevent your company's users from accessing IBM products and offerings.
From the above screenshot, “Verification certificates (optional)” field is set to "No". Therefore, this SAML identity provider implementation does not verify authentication request signatures.
From the above screenshot, “Require verification certificates” is unchecked. Therefore, this SAML identity provider implementation does not verify authentication request signatures.
If using another SAML identity provider implementation with IBMid, please verify if your SAML settings does not require verification certificates. If it does not require, then no action is needed regarding this IBMid Signing Certificate Update. However, if your SAML settings does require verification certificates, please contact your identity provider administrator or your IT department who manages SAML SSO to act on this IBMid Signing Certificate Update notice.