Hey all, Dave from Okta here - I wrote this template a few years back to notify admins of any soon-to-expire SAML certificates in their org. In its current form, it will work for up to 2000 apps, but it’s easily modifiable to process as many as you need.
Thanks Dave & Max. I’m a new user, the forum is still not allowing me to upload a picture.
Would make sense, I don’t have Google or O365 connections. Anyway, I can modify the download to remove that requirement? Also do you happen to know if it supports the SAML encryption cert expiry? That’s what we are after.
Ok, try this one - I removed the Gmail and O365 cards. You’ll just need ot come up with a way to notify someone if a cert is expiring… dcCertificateExpirationWarningNoEmail.folder (290.6 KB)
Great flow. It’s saved me a lot of work. It handles the SAML certificates from the Okta side, however there is one thing missing from the report. We have some SAML integrations where we use the vendor supplied SAML certificate for encryption which has it’s own expiration date.
If you query an app which has a SAML encryption certificate /api/v1/apps/${appId}
then search for “x5c” you will find the vendor provided certificate. The cert is missing the begin/end. Also the \r\n need characters need to be replaced with line feeds to recreate the certificate.
I wondered if you or anyone in the forum had a workflow that retrieved that too?