Suggested answer

Trust is certificate-based. I give Salesforce the identity provider's issuer value and its public signing certificate. From then on, Salesforce accepts an assertion if it is signed by the matching private key, names this org as the audience, and is addressed to this org's Assertion Consumer Service endpoint. There is no shared secret and no requirement for a common public certificate authority — self-signed identity provider certificates are normal, because Salesforce trusts the specific certificate I uploaded.

What breaks it, in the order I see it: a signing certificate that expired and was rotated at the identity provider without being replaced in Salesforce; a My Domain change or a sandbox refresh that moves the audience and ACS URL out from under an identity provider still pointing at the old values; and clock drift on the identity provider host, which pushes assertions outside their validity window and produces intermittent failures.

The operational lesson I bring to design reviews is that certificate rotation needs to be a calendared, owned process on both sides. It is the most predictable outage in the whole identity stack and it is always treated as a surprise.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.