You have noticed that the MuleSoft Anypoint SSO signing certificate is expiring soon or has already expired.
For the MuleSoft Anypoint SSO signing certificate, the SAML specification states that SAML certificates can be expired. Per section "2.5.1 Key Representation" in this link: https://docs.oasis-open.org/security/saml/Post2.0/sstc-metadata-iop.html.
In the case of an X.509 certificate, there are no requirements as to the content of the certificate apart from the requirement that it contain the appropriate public key. Specifically, the certificate may be expired, not yet valid, carry critical or non-critical extensions or usage flags, and contain any subject or issuer. The use of the certificate structure is merely a matter of notational convenience to communicate a key and has no semantics in this profile apart from that. However, it is RECOMMENDED that certificates be unexpired[1].
If the Anypoint expired certificate is a cause of concern, the following explains the process of providing your own certificate/key pair or having the Anypoint platform generate a self-signed certificate for you to use.
You can now rotate in a new pair of Anypoint keys, but you must complete the prequisites first.
https://docs.mulesoft.com/access-management/managing-users#prerequisites
Step 1:
- Access Management - Identity Providers - SAML edit - Copy the new ACS URL
- Anypoint Keys - New Key - Generate (Do NOT set as primary key yet) - download the key
Step 2:
- Replace your IDP Anypoint's current ACS from
https://anypoint.mulesoft.com/accounts/login/receive-id
and paste in your ACS URL
https://anypoint.mulesoft.com/accounts/login/<DOMAIN>/providers/<PROVIDER-ID>/receive-id
- Upload the new certificate key to your IDP.
Step 3:
Set the new key as primary. Test again to make sure you are able to login.
NOTE: In case an Admin who gets locked out and cannot log into AnyPoint portal to rotate the certificate needs alternate method of login.
001120588

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.