Our SSO certificate expired
If you do not have any Keeper administrators that are able to log in to the admin console using a master password, please renew the certificate on your Identity Provider (IdP) side and ensure it is active.
Once updated, export the XML metadata and provide it to Keeper Business Support via the following channels for further assistance.
Email : business.support@keepersecurity.com
You can reference our Certificate Renewal Guide for specific instructions.
If you do have a Keeper administrator that is currently able to log to the admin console, please refer the following instructions in order to update your SSO certificate.
1. Access the Keeper Admin Console Log in to your Keeper tenant using the appropriate link for your region:
US: keepersecurity.com/console
AU: keepersecurity.com.au/console
US Gov: govcloud.keepersecurity.us/console
2. Update the SAML Metadata
Step 1: Navigate to the SSO Node and select the Provisioning tab.
Step 2: Select Single Sign-On with SSO Connect Cloud.
Step 3: Click Edit Configuration.
Step 4: Clear out the existing SAML Metadata.
Step 5: Upload (drag and drop) the new XML metadata file from your desktop.
Step 6:Save the configuration. Your SAML certificate is now updated.
3. Verify & Cleanup
Confirm that users can now log in via SSO without errors. Delete the metadata XML file from your local computer or store it securely within your Keeper Vault. We recommend creating a calendar reminder to update your SAML certificate next year prior to its expiration date.
Relying solely on SSO for all administrators creates a risk where no one is available to approve new devices or access the vault during an IdP outage. We recommend creating an administrator "service account" that uses a strong Master Password, 2FA, and optionally IP Allowlisting to optimally secure the account.
In situations where all administrators use SSO and are on new, unapproved devices, Keeper Support is unable to facilitate recovery. By design, Keeper is a zero-knowledge platform; our team cannot approve SSO-enabled devices or recover device-encrypted data keys for users.
For more details regarding the Service account/Break Glass account, please refer to our documentation here.