Understanding SSL certificates
Who is this article for?
Users who want to learn about SSL certificates.
Server access may be required for on premise customers.
This article explains SSL certificates used with Please Review and how they are updated.
1. Website
If your site is:
- A standard hosted site with us (https://company.pleasereview.net/), our Cloud Ops team will handle SSL certificate renewal and customers need to do nothing.
- A site hosted with us using a custom domain, you must provide an updated SSL certificate before expiry so our Cloud Ops team can schedule the update. Please inform us when to make the change.
- For self-hosted setups, SSL certificate renewal is your responsibility.
2. Authentication (SSO)
Native PR SAML2 Configuration
The updated SSL certificate for the external authentication login method on Please Review must be stored with the configuration files on the server. It is included in the metadata file and the Runtime\config\systemconnector.xml needs to be updated to point to this. Both the background service and web application needs to restarting so any logged in users will be logged out, when applying this change. (It is recommended to keep the old file, renaming it, if need be, as a fallback, just in case)
For hosted customers, this updated SSL certificate needs to provided to be Ideagen in advance. This allows our Implementation Team, who normally deal with installation configurations like this, to schedule the update. Please inform us of a suitable time to make the change.
Ideagen Hub SAML2 Configuration
The updated SSL certificate can be updated by the Hub tenant admin user without needing to involve Ideagen. Users should remember to update this before it expires.
It is also recommended to keep a tenant admin login that uses a different login method than the SAML2 one to ensure users always retain access to the Hub, as if you forget to update this before it expires, and you have no other valid login for it, you would need to contact Support, who can then request internally to get access to this.