<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Create a CA-Signed Certificate for Okta Palo Alto Networks SAML Applications

Single Sign-On
Okta Classic Engine

Overview

Palo Alto Networks (PAN) requires a Certificate Authority (CA) to validate certificates in the Secure Assertion Markup Language (SAML) assertion due to a security issue with PAN firewalls (CVE-2020-2021). To meet this requirement, administrators must replace the self-signed Identity Provider (IdP) certificate in Okta Palo Alto Networks applications (for example, GlobalProtect) with a CA-signed certificate.

Applies To

  • Okta Classic Engine
  • Palo Alto Networks (PAN)
  • Certificate Authority (CA)
  • Secure Assertion Markup Language (SAML)

Solution

How is a CA-signed certificate created for Palo Alto Networks SAML applications?

Generate a CA-signed certificate and enable the validation setting on the PAN-OS by following the Palo Alto Networks instructions.

Review the Steps to configure CA-issued certificate and enable Validate Identity Provider Certificate on PAN-OS.

 

NOTE: Okta provides a script on this GitHub page that performs the steps outlined in the Palo Alto Networks documentation. A certificate authority must still sign the Certificate Signing Request (CSR), as the script cannot automate the signing operation.

 

Related References

Loading
Create a CA-Signed Certificate for Okta Palo Alto Networks SAML Applications | Okta Support