To secure your installation, you must generate new key new key pairs. If you do not generate new key pairs, then the default certificates that the STS inherently trusts are used. To increase security you should generate a new unique certificate for each SSO component.
When this feature is activated in the SBM configurator, the RM server must be added to the “Select additional hosts that are allowed for SSO”. If this RM server is NOT added, the message "403 Error – Forbidden