<div dir="ltr">Salesforce uses self-signed signing certs with 1 year lifetime, and it's time to swap.<div>I think I can ease the transition by adding the new cert initially without removing the old in their metadata, and the IdP is smart enough to rely on the right cert; then after the switch is verified, remove the old. Am I correct?</div><div><br></div><div>David Bantz</div></div>