Create a CA-Signed Certificate for Okta Palo Alto Networks SAML Applications
Last Updated:
Overview
Palo Alto Networks (PAN) requires a Certificate Authority (CA) to validate certificates in the Secure Assertion Markup Language (SAML) assertion due to a security issue with PAN firewalls (CVE-2020-2021). To meet this requirement, administrators must replace the self-signed Identity Provider (IdP) certificate in Okta Palo Alto Networks applications (for example, GlobalProtect) with a CA-signed certificate.
Applies To
- Okta Classic Engine
- Palo Alto Networks (PAN)
- Certificate Authority (CA)
- Secure Assertion Markup Language (SAML)
Solution
How is a CA-signed certificate created for Palo Alto Networks SAML applications?
Generate a CA-signed certificate and enable the validation setting on the PAN-OS by following the Palo Alto Networks instructions.
Review the Steps to configure CA-issued certificate and enable Validate Identity Provider Certificate on PAN-OS.
NOTE: Okta provides a script on this GitHub page that performs the steps outlined in the Palo Alto Networks documentation. A certificate authority must still sign the Certificate Signing Request (CSR), as the script cannot automate the signing operation.
