Managing expired SSO certificates
Last updated: December 17, 2025
Overview
If you’ve received emails from Salesforce about an expired SSO certificate, you may be unsure whether it’s safe to remove. In most cases, this certificate is a legacy artifact no longer used by amplo or our customers. This article explains how to safely assess and remove the certificate.
Process
Before deleting the certificate, always create a backup so you can restore it if needed.
From Setup, use the Quick Find search bar to find Certificates and Key Management to view the Certificates in your Salesforce org.
Find the certificate, and click Download Certificate.
Save the file in a secure location.
Next, delete the expired certificate.
Best practices
After deletion, monitor your system to ensure there are no unexpected impacts.
Always create a backup before removing any certificate, even if it appears unused.
Retain backups in a secure location to ensure quick recovery if any dependent process is unexpectedly affected.
Troubleshooting
If you encounter issues after removing the certificate:
Restore it by importing the backup file you downloaded.
Note: This certificate type cannot be exported in Keystore format. The Download option is the only available backup method.
If problems persist or you are unsure whether removal is safe for your org, contact amplo support for assistance.