Note:
Applies to: Core Modules (such as Recruitment ATS and Performance).
This certificate rotation does not apply to Recruitment Marketing. For Recruitment Marketing, refer to the Recruitment Marketing - Security section for details.
Announcement: On 11 Feb 2026 AEDT, the PageUp Public Key for SAML Single Sign On (SSO) will expire. As your organization logs in to PageUp using SAML SSO, you may need to upload an additional key to your SSO infrastructure.
This page is intended for system Superusers and Technical Contacts who manage SAML SSO Identity Providers.
What is the PageUp Public Key?
PageUp's Public Key for SAML SSO is a key that is uploaded to some SAML SSO Identity Providers listing PageUp as an authorized SSO service. This is used by identity providers such as ADFS and Shibboleth for authenticating connections via SAML SSO.
What is changing?
- According to standard security practices, Public Keys have a limited usage period and must then be rotated. The PageUp Public Key will be expiring on 11 Feb 2026, and a replacement Public Key is in place.
- The new Public Key is now active and will be required on 11 Feb 2026. Please use the PageUp Metadata URL to upload the additional certificate to your Identity Provider (IDP) in preparation for this activation.
- PageUp will remove the expired key after 11 Feb 2026.
- The PageUp Metadata URL has been updated to include the new certificate. This Metadata is compatible with SAML, ADFS, and Shibboleth automatic Metadata retrieval.
What do I need to do?
A member of the team responsible for managing your SSO systems will be familiar with this process. Please ensure they are aware of this notification and have actioned it if required, especially if using ADFS or Shibboleth as the IDP, or have SAML request encryption enabled.
Details for the SSO Technical Team
- The Public Key expiry is relevant to all customers using ADFS & Shibboleth Identity Providers.
- OKTA & Entra ID (formerly Azure AD) will also require the public key if the requests are encrypted or if the advanced option Signed requests is enabled. In the absence of either of these two settings being enabled, OKTA and Entra ID (formerly Azure AD) do not require the public key; therefore, you may regard this as an informational notification only, with no action necessary.
- The PageUp Metadata URL is not changing, only the content within it.
- If you have previously configured one of the below URLs, then running the automated process to refresh the content will be all that's required.
- For those SAML Identity Providers which accept Metadata, the PageUp metadata for your region may be accessed below.
If your IDP does not support links to Metadata, you may need to download the files as a file. To download the files below, please right-click the link and select the Save link as option.
Live/Production:
- AU: https://metadata-sso.pageuppeople.com/dc2/live/metadata.xml
- EMEA: https://metadata-sso.pageuppeople.com/dc3/live/metadata.xml
- USA: https://metadata-sso.pageuppeople.com/dc4/live/metadata.xml
- APAC: https://metadata-sso.pageuppeople.com/dc5/live/metadata.xml
UAT:
- AU: https://metadata-sso.pageuppeople.com/dc2/uat/metadata.xml
- EMEA: https://metadata-sso.pageuppeople.com/dc3/uat/metadata.xml
- USA: https://metadata-sso.pageuppeople.com/dc4/uat/metadata.xml
- APAC: https://metadata-sso.pageuppeople.com/dc5/uat/metadata.xml
The Metadata file will include the following:
- X509Certificate (certificate details)
- validUntil (expiry date)
- protocolSupportEnumeration (protocol)
- entityID
- AssertionConsumerService (assertion endpoints)
Where the Identity Provider does not accept metadata, you may retrieve the new Public Key and create a certificate for manual upload to your Identity Provider.
PageUp recommends the use of the above Metadata where possible.
New PageUp Public Key
Here is a Base64 version of the PageUp public key; please download this version.
You will need to rename the extension of the downloaded file from *.TXT to *.CER
Extract the Public Key from PageUp Metadata file
Access the PageUp metadata from the relevant link above.
- x509Certificate (There are 2 signing certificates, with a x509Certificate “tag” each; please generate both certificates, and update your IDP to include the one that is not currently installed.)
Steps to create a .cer file from the Metadata file (follow exactly without removing):
- Open the Metadata URL in a browser or download and save as XML and open in a text editor
- Copy the details within the
<x509 certificate>tag of the metadata file until the end of tag</x509 certificate>(see below screenshot in step 8). - Open Notepad (on Windows).
- Type in
-----BEGIN CERTIFICATE-----(Do not omit any of the dashes). - Press Enter.
- Paste in the details you copied earlier (step 2 above).
- Press Enter.
- Type in
-----END CERTIFICATE-----(Do not omit any of the dashes). Your certificate should look similar to the example below. - Click File and then click Save As.
- Choose your folder location by selecting it (tip: save it to your "Desktop" folder).
- Change the Save as type to All Files.
- Add
.cerin the File name. e.g., certexamplefile.cer - Click Save.
This certificate file may then be manually uploaded into your ADFS or other Identity Provider.
Changeover Process
Where SAML Identity Provider (IDP) holds concurrent certificates and a new one is uploaded (ADFS & standard Shibboleth):
- The customer consumes PageUp Metadata.
- Old and new certificates are installed on the IDP.
- 11 Feb 2026 AEDT: PageUp will update to sign using the new (expiry 2027) SAML Public Key
- The customer is to remove the old certificate from being installed on the IDP (recommended but not required).
It is also possible for PageUp to configure your PageUp Account to sign with the New Public Key ahead of 11 Feb 2026 on request. Please refer to the below for details.
When a custom SAML IDP supports only one Public Key
Where the SAML IDP can hold only one certificate, the configuration of both systems will need to be updated at the same time. To minimize disruption, PageUp recommends organizing a Teleconference session during normal business hours, including the following recommended attendees:
- IDP Administrator: To make the change in real time.
- PageUp Superuser from your organization: To test the SSO before and after the changeover (not required if the IDP Admin can SSO into PageUp).
- PageUp Representative: To make the PageUp changes detailed below in real time and provide monitoring.
The process where only a single certificate may be held in the IDP:
- Begin teleconferencing session.
- Update IDP to the new public key.
- During the implementation of this update, PageUp is able to modify the configuration to utilise signing with the new Public Key.
- Test and monitor logging (troubleshooting if required).
This process typically takes between 5 - 10 minutes.
It's important to note that users attempting to access PageUp during the changeover period may encounter authentication issues.
Please email support@pageuppeople.com to request a changeover be scheduled.
Update Configuration in PageUp
Once both certificates are present in the SAML IDP, the final (optional) step is to update your PageUp system to sign requests with the new PageUp Public Key
Although this step is optional, it should only be undertaken after the new PageUp Public Key has been uploaded alongside the current (expiring) one. We strongly recommend that the Superuser performing this change liaises with your SSO team and that another SSO-enabled user is available to complete testing. This process requires a PageUp user with Superuser permissions.
To update the setting in PageUp, please follow the steps below:
- Log in to your PageUp Live/Production environment (or UAT if relevant).
- From the side menu, click Settings.
- Search for and click on SAML certificate signing thumbprint.
- Click the Edit (pen) icon.
- Update the value from the existing value to be:
CB635F494C81821908D449AF4F96AF69166DB7BF- Do not include additional spaces at the start or end of the value) - Click Save.
- Finally, click the Save changes button at the bottom of the Settings page.
- Request that another user with SSO access to the system attempt to sign in to PageUp via SSO. This will enable you to revert the change if they are unable to log in.
- Retest again after an additional 3 minutes.
- If the user receives an "Authentication failed" message while testing, please input the original thumbprint value (
8A3405F27B7FD35DD200A77AF59AA40A4DA62247) to roll back the change. - Upon successful completion of testing, the SSO team will be authorized to remove the expiring certificate from the IDP, should they wish to do so.
Testing in UAT
As this constitutes a routine change, User Acceptance Testing (UAT) is not anticipated to be necessary. Conducting tests in the UAT environment would likely necessitate the implementation of Single Sign-On (SSO) within either your Development Identity Provider (Dev IDP) or PageUp UAT. Therefore, testing may be provided on an exceptional basis if deemed necessary.
FAQs
Can PageUp confirm if we're using the latest SAML SSO Public Key?
No, we are unable to determine this; the team responsible for your SAML Identity Provider will be able to provide this information. There is an action that PageUp can undertake, which requires the new certificate prior to its expiry. Should Single Sign-On (SSO) cease to function following the configuration change, this will indicate that your IT team must take appropriate measures. Please note that this method of validation is highly disruptive and is therefore not recommended.
We use Entra ID (formerly Azure AD) or Okta as our IDP; do we need to update the certificate?
Entra ID (formerly Azure AD) and Okta do require the public key if requests are encrypted. If requests are not encrypted, it is not necessary to install a copy of the PageUp SAML token signing certificate within the IDP.
We use PingID as our IDP. Do we need to update the certificate?
PingID requires the public key if requests are not encrypted or if Require digitally signed AuthN is enabled. If requests are not encrypted and the setting Require digitally signed AuthN request is set to False, then this notification is for informational purposes only.
We don't upload a Public Key in our SAML SSO Identity Provider; is action required?
PageUp recommends that you continue to use the Metadata URL, even if your Identity Provider does not require you to upload a SAML Public Key.
What is the Metadata URL?
Please see the list of Metadata URLs above.
Which of the Metadata URLs is relevant to my organisation?
The original notification received concerning this update will include the Metadata URL specific to your region. PageUp provides distinct Metadata URLs for each region. These regions are identified by the DC (for example, DC2 for Australia, DC3 for Europe, etc.) within the URL of the metadata link. When users are logged into PageUp, the URL will indicate the DC corresponding to the region to which they are logged in.
When does the current Public Key expire?
11 February 2026
What will happen if we don't update to the new Public Key?
In cases where your SAML Identity Provider requires the Public Key to connect to PageUp servers, users will receive an "Authentication Failed" message when attempting to access PageUp via SSO after 11 February 2026.
Is PageUp currently signing with the new or old certificate?
PageUp is signing SAML responses with the old public key (expires 11 February 2026). The new key will activate on 11 February 2026.
What time of day will PageUp be activating the new public key?
PageUp will be activating (signing) the New Public Key between 8 AM and 5 PM AEDT.
Is it possible to update PageUp to sign with the New public key only?
For customers utilising IDPs that are unable to accommodate both the old and new public keys simultaneously, PageUp can configure your PageUp Account to sign using the New Public Key instead.
Do we need to update the certificate for UAT?
For customers utilising IDPs that maintain the PageUp token signing certificate (such as ADFS and Shibboleth), if you have a distinct and separate SSO infrastructure connected to your UAT environment and use it regularly, it is advisable to update the certificate. Otherwise, you should not update it or remove the UAT configuration.
Do you have guides on how to manually update the certificate in ADFS?
Customers using ADFS IDP who prefer not to use the recommended metadata URL can find manual instructions here (see section 4. Signature). You must be logged into the Knowledge Portal to access these details.
Troubleshooting
Viewing complete metadata:
Some customers report no binding on the Entity Descriptor in Mozilla Firefox metadata view. Please use Google Chrome as a workaround.
Metadata URL - Expiry date (validUntil):
To enable automatic retrieval of PageUp Metadata for SSO, a metadata expiry date (validUntil) is included. After expiry, your IDP should fetch the latest version from our servers. If you manually download and install the metadata without automated retrieval, you must update this date yourself by editing the XML <SPSSODescriptor><validUntil> value before importing it to your IDP.
400 Bad Request Okta:
Okta users are getting a 400 Bad Request error despite successful SSO logs. This happens because the current public signing certificate hasn't been uploaded to Okta, while the Signed requests setting is enabled. Per Okta documentation, the Signed requests option appears only after uploading a certificate in the Signature Certificate field. To fix the error, upload the current PageUp public signing certificate into the Signature Certificate field.
ADFS Error Messages:
Several clients have reported that their ADFS is unable to process metadata when updating existing configurations, encountering one of the following error messages:
- Error message: MSIS7508 The metadata contains unexpected data. Conflicting encryption certificates were identified within the RoleDescriptors required to represent a service provider role.
- MSIS0038: SAML Message has an invalid signature.
Should your ADFS be unable to process the Metadata URL, please extract and manually upload both the old and new certificates from the Metadata URL.
Alternatively, you may download the certificates provided below, rename them with a .cer extension, and then upload them.
These certificates are compatible with both Live/Production and UAT environments.
Once both certificates have been uploaded, the configuration should resemble that of previous years, as illustrated below.
Comments
Article is closed for comments.