Migrating your identity provider to use the new service provider certificate

Impact on Enterprise Video Streaming authentication

The service provider certificate for Enterprise Video Streaming (EVS) is set to expire on March 24, 2025. If your Identity Provider (IdP) verifies authentication request signatures, you must update your configuration to use the new certificate.

New Service Provider Certificate

Please update your IdP configuration with the following certificate:

-----BEGIN CERTIFICATE-----

MIIEAzCCAuugAwIBAgIUXWtayjLAJ4m/aw0W2yoLiQY2rr0wDQYJKoZIhvcNAQEL

BQAwgZAxCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazEPMA0GA1UEBwwG

QXJtb25rMTQwMgYDVQQKDCtJbnRlcm5hdGlvbmFsIEJ1c2luZXNzIE1hY2hpbmVz

IENvcnBvcmF0aW9uMScwJQYDVQQDDB5leHRhdXRoLnNlcnZpY2VzLnZpZGVvLmli

bS5jb20wHhcNMjUwMjEwMjMwMDAwWhcNMzUwMzI0MjMwMDAwWjCBkDELMAkGA1UE

BhMCVVMxETAPBgNVBAgMCE5ldyBZb3JrMQ8wDQYDVQQHDAZBcm1vbmsxNDAyBgNV

BAoMK0ludGVybmF0aW9uYWwgQnVzaW5lc3MgTWFjaGluZXMgQ29ycG9yYXRpb24x

JzAlBgNVBAMMHmV4dGF1dGguc2VydmljZXMudmlkZW8uaWJtLmNvbTCCASIwDQYJ

KoZIhvcNAQEBBQADggEPADCCAQoCggEBALyuZ2K1ITZLR2TkUHlzb5zhrEy9T1tL

6IV6X2kWqT1OCNiaP48FE2dAH8X23UnKm854/5eEoEvVVQ1b749/W+WTKcqzDmOG

zt4UjXsaMWfNU0QWytogtm3hv16b+x3WJ+xa0eRKZtFzaPCUAfvI87STxi01/ADV

Pd9BnPvBkJJ0Cla8uApfvla/uos5X31qoEfYbl4WrfWID12kwYnJgJgp1gpnIRcm

r4RMQgl3nIst8qySNiXITRWSwfqOi2CqB+Hf+53cifp1fQABazgwF8JozY/6xxCF

QoY8r62p2JnDcSFVSkpJ8+fjeexhxnnawbyf13OfbkkZ5kkG0nIVt4cCAwEAAaNT

MFEwHQYDVR0OBBYEFEQ3BBeytAm06IAHuYSu08Go8Y8OMB8GA1UdIwQYMBaAFEQ3

BBeytAm06IAHuYSu08Go8Y8OMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQEL

BQADggEBAEC/IKvLo1P+RTHa8WJA9nKSPChf8rfe91n5h/c72aDzBELXxS8kz4dX

Xp0fVFVPf8FlMwSb2ek/9KZODNwgOZJUFbB0EKEkKQvhjSre4UVd7n8MHeZCxAfr

UnPN1lTYqPGmV/hTIlIB5hrPwo8yviS5Mf6jROtoMUV0svCExFpnQpqFGrrOkN19

4v6ryo5Rz8S3vKziN/7r9x2IRsGmP+wABEwmMdX5av3YX8/P9TISzF20A99xMX0t

JJ36mHUw+ONAY5vI2oW4LKavMv/90iQvuWeP3ksRiUovzjiVVuhIEInVqFvFr6uZ

Zs1M1vAb7n5Jimz+BalFt4qA4LNF+qw=

-----END CERTIFICATE-----

 

 

Updated Service Provider Metadata

If your integration relies on metadata.xml, you can retrieve the latest service provider metadata with the updated certificate at https://extauth.services.video.ibm.com/saml?version=2

 

Confirm Your Migration

Once you have updated your IdP with the new certificate, you must confirm the change in your EVS security settings:

  1. Navigate to the Security Settings Dashboard at https://video.ibm.com/dashboard/integrations/security
  2. Locate the section "Service provider certificate version used".
  3. Select "New certificate (valid until March 24, 2035)" from the dropdown.
  4. Click Save.
  5. Verify your integration by logging into the EVS portal, an EVS channel page


Screenshot 2025-02-18 at 12.18.48 PM.png

Impact on Organization Logins

Clients who have configured their dashboard login method to use SAML authentication must update their IdP with the new certificate. If your organization relies on SAML for authentication, failure to update the certificate may result in login disruptions for your administrators.

The service provider certificate for Organization logins is set to expire on March 24, 2025. If your Identity Provider (IdP) verifies authentication request signatures, you must update your configuration to use the new certificate.

 

New Service Provider Certificate


Please update your IdP configuration with the following certificate:

-----BEGIN CERTIFICATE-----

MIIEAzCCAuugAwIBAgIUXWtayjLAJ4m/aw0W2yoLiQY2rr0wDQYJKoZIhvcNAQEL

BQAwgZAxCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhOZXcgWW9yazEPMA0GA1UEBwwG

QXJtb25rMTQwMgYDVQQKDCtJbnRlcm5hdGlvbmFsIEJ1c2luZXNzIE1hY2hpbmVz

IENvcnBvcmF0aW9uMScwJQYDVQQDDB5leHRhdXRoLnNlcnZpY2VzLnZpZGVvLmli

bS5jb20wHhcNMjUwMjEwMjMwMDAwWhcNMzUwMzI0MjMwMDAwWjCBkDELMAkGA1UE

BhMCVVMxETAPBgNVBAgMCE5ldyBZb3JrMQ8wDQYDVQQHDAZBcm1vbmsxNDAyBgNV

BAoMK0ludGVybmF0aW9uYWwgQnVzaW5lc3MgTWFjaGluZXMgQ29ycG9yYXRpb24x

JzAlBgNVBAMMHmV4dGF1dGguc2VydmljZXMudmlkZW8uaWJtLmNvbTCCASIwDQYJ

KoZIhvcNAQEBBQADggEPADCCAQoCggEBALyuZ2K1ITZLR2TkUHlzb5zhrEy9T1tL

6IV6X2kWqT1OCNiaP48FE2dAH8X23UnKm854/5eEoEvVVQ1b749/W+WTKcqzDmOG

zt4UjXsaMWfNU0QWytogtm3hv16b+x3WJ+xa0eRKZtFzaPCUAfvI87STxi01/ADV

Pd9BnPvBkJJ0Cla8uApfvla/uos5X31qoEfYbl4WrfWID12kwYnJgJgp1gpnIRcm

r4RMQgl3nIst8qySNiXITRWSwfqOi2CqB+Hf+53cifp1fQABazgwF8JozY/6xxCF

QoY8r62p2JnDcSFVSkpJ8+fjeexhxnnawbyf13OfbkkZ5kkG0nIVt4cCAwEAAaNT

MFEwHQYDVR0OBBYEFEQ3BBeytAm06IAHuYSu08Go8Y8OMB8GA1UdIwQYMBaAFEQ3

BBeytAm06IAHuYSu08Go8Y8OMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQEL

BQADggEBAEC/IKvLo1P+RTHa8WJA9nKSPChf8rfe91n5h/c72aDzBELXxS8kz4dX

Xp0fVFVPf8FlMwSb2ek/9KZODNwgOZJUFbB0EKEkKQvhjSre4UVd7n8MHeZCxAfr

UnPN1lTYqPGmV/hTIlIB5hrPwo8yviS5Mf6jROtoMUV0svCExFpnQpqFGrrOkN19

4v6ryo5Rz8S3vKziN/7r9x2IRsGmP+wABEwmMdX5av3YX8/P9TISzF20A99xMX0t

JJ36mHUw+ONAY5vI2oW4LKavMv/90iQvuWeP3ksRiUovzjiVVuhIEInVqFvFr6uZ

Zs1M1vAb7n5Jimz+BalFt4qA4LNF+qw=

-----END CERTIFICATE-----

 

Updated Service Provider Metadata

If your integration relies on metadata.xml, you can retrieve the latest service provider metadata with the updated certificate at https://extauth.services.video.ibm.com/saml?version=2

Confirm Your Migration

Once you have updated your IdP with the new certificate, you must confirm the change in your oragnization security settings:

  1. As an organization administrator navigate to the Organization Settings > SSO login Dashboard at https://video.ibm.com/ organization/[org_id]/settings/sso
  2. Locate the section "Service provider certificate version used".
  3. Select "New certificate (valid until March 24, 2035)" from the dropdown.
  4. Click Save.
  5. Verify your integration by logging into the dashboard using your SSO credentials. 
    Screenshot 2025-02-18 at 12.27.18 PM.png

 

Need Assistance?

If you encounter any issues updating your certificate, please contact EVS Support for assistance.



Powered by Zendesk