Hi all,
How does the system handle the encryption of the metadata when updating the identity provider? I apologize if this is a beginner question, but we’re doing a SOC2 audit and the security team is asking about the data residency of the SAML certificates.
We’ve tried to update the configuration using PUT /api/v2/identityproviders/generic to ensure the new certificate is pushed. The request returns a 400 Bad Request error. It says the payload is invalid, but the XML looks correct to me.
{
"name": "Corporate-IdP",
"idpEntityId": "https://sts.windows.net/tenant-id/",
"idpCertificate": "MIIC8DCCAdigAwIBAgI...",
"ssoUrl": "https://login.microsoftonline.com/tenant-id/saml2"
}
The audit requires us to prove that the encryption keys for the SSO handshake aren’t stored in plain text in the backend. I’m not sure if “security profile” is the right term here or if this is a different setting. We’re on Genesys Cloud in the Asia-Tokyo region.