In this article
dropdown icon
Renew expiring certificates
    Renew a Webex Service Provider (SP) certificate
    Renew an IdP certificate
dropdown icon
Manage SSO metadata
    Download Webex SP metadata for your IdP
    Upload IdP metadata to Webex
Manage SSO alerts
Understand Single Logout
Disable single sign-on
SSO self recovery
Manage single sign-on integration in Control Hub
list-menuIn this article
list-menuFeedback?

Use the single sign-on (SSO) management features in Control Hub for certificate management and general SSO maintenance activities, such as updating an expiring certificate or checking on your existing SSO configuration. Each SSO management feature is covered in the individual tabs in this article.

If you want to set up SSO for multiple identity providers in your organization, refer to SSO with multiple IdPs in Webex.

A vulnerability was identified in the single sign-on (SSO) certificate validation process for Cisco Webex Services by the Cisco Security and Trust team. As a result, the SSO trust anchors will be removed on May 22, 2026. To ensure uninterrupted access to Webex, please upload a new certificate template to Control Hub before this date.

If you are unable to upload the new certificate in time, users will be unable to sign in to Webex. In this case, you can use the SSO self recovery option to temporarily disable SSO and regain access to your Webex organization. To upload a new certificate, refer to the Identity provider (IdP) certificate section in this article.

Renew expiring certificates

Keep your SSO certificates up to date to avoid sign-in interruptions. If an SSO certificate expires, users may lose access to Webex services. The following tasks walk you through the renewal process for the Webex service provider certificate and the IdP certificate.

Renew a Webex Service Provider (SP) certificate

You might receive an email, a Webex App message, or a notification in Control Hub when the Webex single sign-on (SSO) certificate is going to expire. You can also check the Cisco SP certificate status at any time in Control Hub by going to Management > Security > Authentication and selecting the Identity provider tab.

Follow the process in this article to retrieve the SSO cloud certificate metadata and add it back to your IdP; otherwise, users may not be able to use Webex services.

If Control Hub shows certificate usage as None but you still receive an expiry alert, continue with the renewal. Your SSO deployment may not use the certificate today, but the certificate may be required for future SSO changes.

If you’re using the SAML Cisco (SP) SSO Certificate in your Webex organization, you must plan to update the cloud certificate during a regular scheduled maintenance window as soon as possible.

All services that are part of your Webex organization subscription are affected, including but not limited to:

  • Webex App (new sign-ins for all platforms: desktop, mobile, and web)

  • Webex services in Control Hub, including Calling

  • Webex Meetings sites managed through Control Hub

  • Cisco Jabber if it's integrated with SSO

Before you begin

Please read all directions before beginning. After you change the certificate or going through the wizard to update the certificate, new users may not be able to sign in successfully.

If your IdP doesn’t support multiple certificates (most IdPs in the market don’t support this feature), we recommend that you schedule this upgrade during a maintenance window where Webex App users aren’t affected. These upgrade tasks should take approximately 30 minutes in operational time and postevent validation.

1

Sign in to Control Hub, then go to Management > Security > Authentication.

You can start the SSO wizard to update the certificate from this page. If you exit the wizard before you complete it, you can return to this page at any time.

2

Go to the Identity provider tab, go to the IdP, and click Next icon.

3

Click Review certificates and expiry date.

This takes you to the Service Provider (SP) certificates page. You can click More menu to download the SP metadata or certificate.

If your organization uses dual certificates, you also have the option to switch a secondary certificate to a primary certificate or delete an existing secondary certificate.

4

Click Renew certificate.

5

Choose the type of IdP that your organization uses.

  • An IdP that supports multiple certificates
  • An IdP that supports a single certificate

If your IdP supports a single certificate, we recommend that you wait to perform these steps during scheduled downtime. While the Webex certificate is being updated, new user sign-ins briefly won't work; existing sign-ins are preserved.

6

Choose the certificate type for the renewal:

  • Self-signed by Cisco—We recommend this choice. Let us sign the certificate so you only need to renew it once every five years.
  • Signed by a public certificate authority—More secure but you'll need to frequently update the metadata.

    Before proceeding to the next steps, ensure you’re ready to renew your certificate and are operating within your organizations change window. Selecting the Self-signed Cisco or Signed by a public certificate authority immediately creates a new certificate. Once the certificate changes for a single IdP, SSO stops until the certificate or metadata is uploaded on the IdP. Therefore, it is important to complete the renewal process.

7

To confirm that you want to replace the current certificate with your selected one, check By clicking Replace a certificate I'll swap the current certificate with my selected one, and then click Replace a certificate.

8

In the Renew Service Provider (SP) certificates page, click Download metadata or Download certificate to download a copy of the updated metadata file or certificate from the Webex cloud.

9

Navigate to your IdP management interface to upload the new Webex metadata file.

  • This step may be done through a browser tab, remote desktop protocol (RDP), or through specific cloud provider support, depending on your IdP setup and whether you or a separate IdP admin are responsible for this step.
  • For reference, see our SSO integration guides or contact your IdP admin for support. If on Active Directory Federation Services (AD FS), you can see how to update Webex Metadata in AD FS.
10

Return to the Control Hub interface. On the Renew Service Provider (SP) certificates page, check I've already updated the metadata for all IdPs, and then click Next.

11

Click Done.

Renew an IdP certificate

You might receive an email, a Webex App message, or a notification in Control Hub when the IdP certificate is going to expire. You can also check the IdP certificate status at any time in Control Hub by going to Management > Security > Authentication and selecting the Identity provider tab.

Because IdP vendors have their own certificate renewal processes, this task covers the steps required in Control Hub, along with generic guidance to retrieve updated IdP metadata and upload it to Control Hub.

You can start the SSO wizard to update the certificate from the Identity provider tab. If you exit the wizard before you complete it, you can return to the same page at any time.

1

Sign in to Control Hub.

2

Go to Management > Security > Authentication.

3

Go to the Identity provider tab and note the IdP certificate status and expiry date.

4

Navigate to your IdP management interface to retrieve the new metadata file.

This step may be done through a browser tab, remote desktop protocol (RDP), or through specific cloud provider support, depending on your IdP setup and whether you or a separate IdP admin are responsible for this step.

For reference, see our SSO integration guides or contact your IdP admin for support.

5

Return to the Identity provider tab.

6

Go to the IdP, click upload and select Upload Idp metadata.

7

Drag and drop your IdP metadata file into the window or click Choose a file and upload it that way.

8

Choose Less secure (self-signed) or More secure (signed by a public CA), depending on how your IdP metadata is signed.

9

Click Test SSO Update to confirm that the new metadata file was uploaded and interpreted correctly for your Control Hub organization. Confirm the expected results in the pop-up window. If the test is successful, select Successful test: Activate SSO and the IdP, and click Save.

To see the SSO sign-in experience directly, we recommend that you click Copy URL to clipboard from this screen and paste it in a private browser window. From there, you can walk through signing in with SSO. This helps to remove any information cached in your web browser that could provide a false positive result when testing your SSO configuration.

After uploading the new certificate, it may take up to 24 hours for the change to take effect.

Your organization's IdP certificate is renewed. You can check the certificate status at any time under the Identity provider tab.

Manage SSO metadata

Use these tasks when you need to exchange SSO metadata between Webex and your IdP. Download Webex SP metadata when your IdP needs the latest Webex configuration. Upload IdP metadata when your IdP certificate or IdP configuration changes and Webex needs the updated metadata.

Download Webex SP metadata for your IdP

You can export the latest Webex SP metadata whenever you need to add it back to your IdP. You'll see a notice when the imported IdP SAML metadata is going to expire or has expired.

This step is useful in common IdP SAML certificate management scenarios, such as IdPs that support multiple certificates where export was not done earlier, if the metadata was not imported into the IdP because an IdP admin wasn't available, or if your IdP supports the ability to update only the certificate. This option can help minimize the change by only updating the certificate in your SSO configuration and post-event validation.

1

Sign in to Control Hub.

2

Go to Management > Security > Authentication.

3

Go to the Identity provider tab.

4

Go to the IdP, click Download and select Download SP metadata.

The Webex App metadata filename is idb-meta-<org-ID>-SP.xml.

5

Import the metadata into your IdP.

Follow the documentation for your IdP to import the Webex SP metadata. You can use our IdP integration guides or consult the documentation for your specific IdP if not listed.

6

When you're finished, run the SSO test using the steps in Renew a Webex Service Provider (SP) certificate.

Upload IdP metadata to Webex

When your IdP environment changes or if your IdP certificate is going to expire, you can import the updated metadata into Webex at any time.

Before you begin

Export the latest IdP metadata from your IdP management interface, typically as an XML file.

1

Sign in to Control Hub.

2

Go to Management > Security > Authentication.

3

Click on Identity provider tab.

4

Go to your IdP, click upload and select Upload Idp metadata.

5

Drag and drop your IdP metadata file into the window or click Choose a metadata file and upload it that way.

6

Choose Less secure (self-signed) or More secure (signed by a public CA), depending on how your IdP metadata is signed.

7

Click Test SSO setup, and when a new browser tab opens, authenticate with the IdP by signing in.

Manage SSO alerts

You'll receive alerts in Control Hub before certificates are set to expire, but you can also proactively set up alert rules. These rules let you know in advance that your SP or IdP certificates are going to expire. We can send these to you through email, a space in the Webex App, or both.

Regardless of the delivery channel configured, all alerts always appear in Control Hub. See Notifications in Control Hub for more information.

1

Sign in to Control Hub.

2

Go to Notifications.

3

Choose Manage > All rules.

4

From the Rules list, choose any of the SSO rules that you'd like to create:

  • SSO IDP Certificate expiry
  • SSO SP Certificate expiry
5

In the Delivery channel section, check the box for Email, Webex space, or both.

If you choose Email, enter the email address that should receive the notification.

If you choose the Webex space option, you're automatically added to a space inside of the Webex App and we deliver the notifications there.

6

Save your changes.

What to do next

We send certificate expiry alerts once every 15 days, starting 60 days before expiry. (You can expect alerts on day 60, 45, 30, and 15.) Alerts stop when you renew the certificate.

Understand Single Logout

Single Logout (SLO) lets users sign out of their Webex session and their IdP session through the same SSO sign-out flow. SLO requires support from your IdP and a configured single logout URL.

You may see a notice that the single logout URL is not configured.

We recommend that you configure your IdP to support Single Logout (SLO). Webex supports both the redirect and POST methods, available in metadata that you download from Control Hub.

Not all IdPs support SLO. Contact your IdP team for assistance. For major IdP vendors such as Azure AD, PingFederate, ForgeRock, and Oracle that support SLO, see the SSO integration guides. Consult your Identity & Security team on the specifics of your IdP and how to configure it properly.

If the single logout URL is not configured:

  • An existing IdP session remains valid. The next time users sign in, they may not be asked to reauthenticate by the IdP.

  • A warning message displays when users sign out of Webex.

Disable single sign-on

You can disable single sign-on (SSO) for your Webex organization in Control Hub when you need to stop using the current IdP configuration, such as when you're moving the organization to a different IdP. Disabling SSO returns authentication to Webex cloud-managed passwords and removes the SAML certificate listings for the organization.

If SSO is enabled but users can't sign in, contact your Cisco partner. The partner can access your Webex organization and disable SSO for you.

1

Sign in to Control Hub.

2

Go to Management > Security > Authentication.

3

Go to the Identity provider tab and click Deactivate SSO.

4

Click Deactivate in the confirmation dialog to disable SSO.

SSO is deactivated and all SAML certificate listings are removed.

When SSO is disabled, users who have to authenticate will see a password entry field during the sign-in process.

  • Users who don’t have a password in Webex App must either reset their password or you must send an email for them to set a password.

  • Existing authenticated users with a valid OAuth Token will continue to have access to Webex App.

  • New users created while SSO is disabled receive an email asking them to create a password.

What to do next

To turn SSO back on with the same IdP or a different IdP, complete the setup flow again. After SSO is reconfigured, user authentication follows the password policy for the IdP integrated with the Webex organization.

SSO self recovery

If you run into problems with your SSO login, you can use the SSO self recovery option to get access to your Webex organization managed in Control Hub. The self recovery option allows you to update or disable SSO in Control Hub.

Was this article helpful?
Was this article helpful?