Desktop SSO Could not establish trust relationship Skip to main content
How satisfied are you with the Okta Help Center?
Thank you for your feedback!
How satisfied are you with the Okta Help Center?
Very Dissatisfied
Very satisfied
Enter content less than 200 characters.
Ask Search:
Jay RyanJay Ryan 

Desktop SSO Could not establish trust relationship

Desktop SSO works fine when used in http / non-ssl mode.  When I enable SSL, bind my certificate and update the configuration OKTA, the SSO agent goes offline with the error "The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel."

I can run the internal test to this Agent (authenticated.aspx) and the site is up on 443 and the certificate is valid internally for us, is there something we are missing?
Kevin TurnerKevin Turner (Okta, Inc.)
I have seen this before, and we removed the Okta IWA module. and then re-installed again, but provided the https/443 paramaters on the second install, and it corrected our problem.

Hope that helps.
Jay RyanJay Ryan
the installer doesn't prompt for the URL, that is configured on the OKTA portal side...I uninstalled and reinstalled and still no luck, I also tried deleting the IWA webapp from the OKTA side and then reinstalling, the URL repopulated with the same http://servername/IWA 
Derek FullerDerek Fuller

Hi Jay,

Did you ever figure out a solution to this problem?  We've been having trouble getting IWA (DSSO) working correctly on anything, but IE and Firefox browsers.  Recently, we started experiencing the exact same issue you mentioned in this question.  Our IWA servers just started going offline as far as Okta's console is concerned.  I can reinstall the DSSO module, so that the IIS site gets rebuilt, and it will come online for a couple minutes and then go offline again.  Can you provide and help?


Gurinder BhattiGurinder Bhatti
I am also facing the same issue. Stood up 2 IWA servers for my prod okta tenant. Both were working fine for a day or so and now both are offline. Tried to resintall agent, and that brought it backonline for a few minutes before it went offline again. 
Also, to note, i have a IWA agent configured for my non prod tenant which has been functioning without issues for months now. 
Anyone figure out what the issue is? 
Brent PlummerBrent Plummer
I also have this issue. Anyone find a fix?