Forum Discussion

Ziv's avatar
Ziv
New member | Level 2
21 days ago
Solved

Does Dropbox SAML SSO support IdP self-signed certificates?

Hello everyone,

I'm integrating Dropbox (as the Service Provider) with our internal IdP using SAML SSO and would like to confirm a few things:

  1. Does Dropbox support using a self-signed certificate on the IdP side for signing SAML Assertions or for the certificate uploaded in metadata?
  2. If self-signed certificates are supported, what operational or validation considerations should we be aware of? If not supported, what alternatives do you recommend?
  • Thanks for your patience Ziv​ 

    Dropbox SAML SSO does support IdP self signed x.509 certificates. As long as the certificate is provided in standard PEM format and included in your IdP metadata, Dropbox can use it to validate signed SAML assertions.

    If you use a self signed certificate, just be sure it is kept up to date and that your team has a process for rotating it before expiration. There is no requirement for the certificate to come from a public certificate authority.

    You can find more details about configuring SSO with Dropbox here: https://help.dropbox.com/security/sso-admin

     

2 Replies

  • Dell_Dropbox's avatar
    Dell_Dropbox
    Icon for Community Manager rankCommunity Manager
    11 days ago

    Ziv​ Thanks for dropping by the community. I just wanted to provide a quick update that I'm looking into tracking down an answer for you on this. I'll provide an update as soon as I hear back. 

  • Dell_Dropbox's avatar
    Dell_Dropbox
    Icon for Community Manager rankCommunity Manager
    9 days ago

    Thanks for your patience Ziv​ 

    Dropbox SAML SSO does support IdP self signed x.509 certificates. As long as the certificate is provided in standard PEM format and included in your IdP metadata, Dropbox can use it to validate signed SAML assertions.

    If you use a self signed certificate, just be sure it is kept up to date and that your team has a process for rotating it before expiration. There is no requirement for the certificate to come from a public certificate authority.

    You can find more details about configuring SSO with Dropbox here: https://help.dropbox.com/security/sso-admin

     

About Security and Permissions

Start a discussion in the Dropbox Community forum to get help with your account security and permissions. Find support from Community members.

The Dropbox Community team is active from Monday to Friday. We try to respond to you as soon as we can, usually within 2 hours.

If you need more help you can view your support options (expected response time for an email or ticket is 24 hours), or contact us on X, Facebook or Instagram.

For more info on available support options for your Dropbox plan, see this article.

If you found the answer to your question in this Community thread, please 'like' the post to say thanks and to let us know it was useful!