---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Do not use demo certificates for active saml configurations \[Updated in Security Center 1.5\]

# Do not use demo certificates for active saml configurations \[Updated in Security Center 1.5\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Control whether demo certificates are used in production SAML configurations.
The demo certificates provided by ServiceNow should not be used in production SAML configurations because they are common among all instances with a known passphrase. If one of the SAML properties using a certificate keystore is
active (require_signed_authnrequest, require_signed_logoutrequest, or encrypt_assertion), then the demo data shouldn't be used. Since demo data is shared among all
instances, there is no integrity guarantee of requests signed with shared certificates. Therefore, any message encrypted by the IDP could be decrypted by a bad actor if intercepted.

## More information {#sc-do-not-use-demo-certificates-active-saml-configurations-plugin__section_qhx_1b1_xwb}

{#sc-do-not-use-demo-certificates-active-saml-configurations-plugin__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.authenticate.sso.saml2.keystore |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | string |
| Recommended value | sys_id of a custom keystore |
| Default value | empty string |
| Category | [Communications](https://servicenow-prod.fluidtopics.net/KYWXOfqNUW0uNGo3zippJA "This control ensures proper encryption using strong algorithms and ciphers. This includes ensuring the recommended version of TLS is used for client connectivity, use of strong cipher suites, use of trusted and signed certificates, ensuring connections are encrypted between components and logging of connection failures.") |
| Security risk | * Severity score: 3.9 * CVSS score: Low {#sc-do-not-use-demo-certificates-active-saml-configurations-plugin__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-do-not-use-demo-certificates-active-saml-configurations-plugin__table_ajc_b43_3kb}

