# SAML SSO: rehearse trust changes

https://thiago.limaesilvatecnologia.com.br/en/artigos/saml-certificate-change/

Published: 2026-09-12

Integrations must survive certificate changes.

Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers.

Reading-path month: June 2026

Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates.

A short architecture article. The technical reference supports the topic; hypothetical scenarios and assessment proposals are editorial analysis, not accounts of personal implementations.

## The architecture decision

Stable federation can conceal operational dependencies until certificate changes. Review how both parties update and verify trust.

## Practical application

Editorial proposal: document identity-provider and application owners, windows and metadata configuration. In a hypothetical integration, explain how to identify active settings on each side.

## How to verify

Rehearse updates, temporary disagreement and rollback in testing. Confirm failures do not lead to disabling validation for quick recovery. Deliver a shared procedure with acceptance and rejection evidence for expected scenarios.

## Sources

- [OWASP — SAML Security Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/SAML_Security_Cheat_Sheet.html). Accessed: 2026-09-12.

[Profile: Thiago Silva | Cyber Architect](https://thiago.limaesilvatecnologia.com.br/en/perfil/)
