- Okta Classic Engine
- Directories
- Desktop Single Sign On (DSSO)
- IWA Agent
- First, acquire and install a valid SSL certificate and install it on the IWA Agent server.
NOTE: Okta Support cannot assist with installing SSL certificates on the IWA server.
-
See the following documents for more details on installing the certificate.
-
Use a certificate that contains one or more Subject Alternative Names (SANs).
-
The IWA Redirect URL must match the CN or SAN listed on the certificate.
-
Wildcard certificates are supported and recommended for multi-agent environments.
- Next, enable SSL for IWA in the Okta Admin Dashboard.
-
Navigate to Security > Delegated Authentication.
-
Select Edit next to On-Prem Desktop SSO.
-
Go to the IWA Agents header and select the pencil Icon next to the appropriate IWA Agent server.
-
Change http to https in the IWA redirect URL.
-
Click Save to close the Window and then press Save again below the IWA Agents menu.
-
