<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Certificate Prompt when Authenticating "Authentication of device via certificate - failure: NO_CERTIFICATE"
Okta Classic Engine
Okta Identity Engine
Multi-Factor Authentication
Overview

After migrating from Device Trust (Classic) to Device Trust on the Okta Identity Engine (OIE) and having an authentication policy rule that requires Registered devices, the following message might be seen in the system log events and receive a certificate prompt when authenticating:

Authentication of device via certificate - failure: NO_CERTIFICATE 
 

rtaImage.jpeg

Applies To
  • Okta Identity Engine (OIE)
Cause

This is expected behavior and will be resolved when migrated to Okta FastPass. It occurs because the server is attempting a Device Trust challenge with a device that does not have a client certificate. The user can still log in, but the device is considered "untrusted".

Solution

Deploy and configure Okta Verify FastPass to the users. See Configure Okta FastPass

Once the application has been installed on the end user's devices, have the users authenticate with FastPass to an application policy that requires the device to be managed.

Upon successful authentication, use Okta Verify to authenticate when accessing the managed applications.


Related References

​​​​​​​

 

Loading
Certificate Prompt when Authenticating "Authentication of device via certificate - failure: NO_CERTIFICATE"