Firstup is renewing the certificate used to sign SAML authentication requests sent from Firstup to customer identity providers (IdPs) on US1. If your IdP validates these requests, action by your IT team is required to avoid disruption to new Firstup initiated sign ins.
| Maintenance window: 13 October 2026. Firstup will publish the maintenance window and confirm completion on the Firstup Status Page. |
Who needs to take action?
You only need to take action if all of the following apply:
- Your community is hosted on US1. I.e. your Creator Studio URL looks like https://studio.onfirstup.com/
- Your organisation uses SAML single sign-on (SSO) for Firstup.
- Your IdP is configured to validate signed SAML authentication requests from Firstup.
- The host name in your Firstup entity ID begins with
advocate.—for example,https://advocate.socialchorus.com/community/community/saml/metadata—or you use a custom URL that redirects to anadvocate.URL, such ashttps://nextup.firstup.com/saml/metadata.
No action is required if:
- Your community is hosted on EU or US2. I.e. your Creator Studio URL looks like https://studio.onfirstup.eu/ or https://studio.us2.onfirstup.com/
- Your organisation does not use SSO for the member experience (desktop and mobile, microapps, Teams, etc.).
- Your IdP does not validate signed SAML requests from Firstup.
- Your Firstup entity ID begins with
auth..
What is changing?
Firstup will replace the public certificate used to sign SAML authentication requests. When the new certificate is deployed, the previous certificate will no longer validate new Firstup-initiated sign-in requests.
Firstup will proactively contact customers who may have signed requests enabled and provide the replacement certificate as a PEM file. Use this PEM file as the recommended source for your IdP configuration.
The replacement certificate will also be available in your Firstup SAML metadata after Firstup completes the maintenance window. Firstup will confirm completion on the Status Page.
Prepare before the maintenance window
Choose the approach that matches your IdP capabilities.
If your IdP supports more than one trusted request signing certificate
Add the new Firstup PEM certificate before the maintenance window, while retaining the current certificate. This allows your IdP to validate requests signed with either certificate during the cutover. After the maintenance window, test a Firstup initiated sign in and remove the previous certificate when appropriate for your IdP and security policy.
If your IdP supports only one trusted request signing certificate
Do not replace the current certificate before the maintenance window. Instead, temporarily disable signed request validation for the Firstup SAML application before the maintenance window. This prevents the IdP from rejecting new Firstup initiated sign-ins when Firstup begins signing with the new certificate.
| Important: Do not disable SAML SSO itself. Disable only the IdP setting that validates signed requests from Firstup. Follow your organisation’s security change procedures and keep validation disabled for the shortest practical time. |
What to do after maintenance is complete
After Firstup confirms completion on the Firstup Status Page:
- If you temporarily disabled signed request validation because your IdP supports only one certificate, add the replacement PEM file to your Firstup SAML application in the IdP, then re-enable validation.
- If you added the replacement PEM file in advance because your IdP supports more than one certificate, no certificate change is needed at this point.
- Test a Firstup initiated sign in.
- If the test is unsuccessful, temporarily disable signed request validation again and contact Firstup Support.
Alternative way to retrieve the replacement certificate
The PEM file supplied by Firstup is the recommended source. If needed, you can also retrieve the certificate from your Firstup SAML metadata after the maintenance window:
After Firstup confirms completion on the Status Page, retrieve the new certificate from your Firstup SAML metadata:
- Sign in to Creator Studio.
- Select your community name in the lower-left corner and choose Go to [Community Name].
-
In the new page URL, remove
/welcome(if present), and add/saml/metadatato the end of the URL.For example: https://advocate.socialchorus.com/community/community/saml/metadata
- Copy or download the X.509 certificate from the XML metadata.
Note: If the metadata page does not load, this indicates that your organisation does not use SSO for the member experience and is not in scope of this change. - Add the new certificate to the Firstup SAML application in your IdP.
- Enable signed-request validation in your IdP.
- Test a Firstup-initiated sign-in.
- If Firstup-initiated sign-in is unsuccessful, disable signed-request validation again and contact Firstup Support for further assistance.
What happens if you do not take action?
After Firstup switches to the new certificate, an IdP that validates signed requests using only the previous certificate may reject new Firstup-initiated sign-ins.
Users who are already signed in are not affected. An expired or replaced certificate does not end an existing user session; it affects new sign-in attempts that require the IdP to validate Firstup’s SAML request.
As a temporary fallback, users may be able to sign in through an IdP-initiated flow—for example, by selecting the Firstup application tile in Okta or their IdP portal. This flow typically does not rely on Firstup sending a signed authentication request to the IdP.
It is recommended that you test this fallback in your environment before the maintenance window. It is not a substitute for adding the replacement certificate and re-enabling signed-request validation.
How to check and temporarily disable signed-request validation
Please check the process for your own SAML single sign-on provider. Below are examples for Okta and Microsoft Entra.
Microsoft Entra ID
- Sign in to the Microsoft Entra admin center.
- Go to Entra ID > Enterprise applications > All applications.
- Select your Firstup SAML application.
- Select Single sign-on.
- Under SAML Certificates, find Verification certificates.
- Select Edit and check whether Require verification certificates is enabled.
If this setting is enabled, your organisation is in scope. Clear this setting before the maintenance window, then add the replacement certificate and re-enable the setting after Firstup confirms completion.
If the setting is not enabled, Entra ID does not validate signed SAML requests from Firstup and no action is required.
Microsoft’s guidance is available in Enforce signed SAML authentication requests.
Okta
- Sign in to the Okta Admin Console.
- Go to Applications > Applications.
- Select your Firstup SAML application.
- Select the Sign On tab and edit the SAML settings.
- Under Advanced Settings, check whether Signed Requests is selected.
If Signed Requests is selected, your organisation is in scope. Clear this setting before the maintenance window, then add the replacement certificate in the Signature Certificate field and re-enable Signed Requests after Firstup confirms completion.
If Signed Requests is not selected, Okta is not validating Firstup’s SAML request signature and no action is required.
For field definitions, see Okta’s SAML application settings reference.
Recommended preparation checklist
Before 13 October 2026:
- Confirm whether your Firstup SAML application validates signed requests.
- Review whether your IdP supports multiple trusted request signing certificates.
- If it does not, arrange an approved temporary change to disable signed request validation before the maintenance window.
- Test IdP-initiated access from your IdP’s application tile as a contingency.
- Ensure your IT and service desk teams are aware of the maintenance window, post-maintenance steps, and fallback option.
Comments
0 comments
Article is closed for comments.